Back to overview

WAGO: Vulnerability in web-based authentication in WAGO 750-8XX Version <= FW07

VDE-2020-027
Last update
05/14/2025 14:28
Published at
09/30/2020 13:06
Vendor(s)
WAGO GmbH & Co. KG
External ID
VDE-2020-027
CSAF Document

Summary

The Web-Based Management (WBM) of WAGOs programmable logic controller (PLC) is typically used for administration, commissioning and updates.
With special crafted requests it is possible to change some special parameters without authentication.

Impact

This vulnerability allows an attacker who has access to the WBM to prevent the loading of the runtime-application after restart of the device by sending specifically constructed requests without authentication.

Affected Product(s)

Model no. Product name Affected versions
750-831/xxx-xxx BACnet/IP Controller 750-831/xxx-xxx Firmware <=FW07
750-852 BACnet/IP Controller 750-852 Firmware <=FW07
750-880/xxx-xxx BACnet/IP Controller 750-880/xxx-xxx Firmware <=FW07
750-881 BACnet/IP Controller 750-881 Firmware <=FW07
750-882 BACnet/IP Controller 750-882 Firmware <=FW07
750-889 BACnet/IP Controller 750-889 Firmware <=FW07
750-885/xxx-xxx Controller 750-885/xxx-xxx Firmware <=FW07

Vulnerabilities

Expand / Collapse all

Published
09/22/2025 14:57
Weakness
Improper Authentication (CWE-287)
Summary

Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW07 allows an attacker to change some special parameters without authentication. This issue affects: WAGO 750-852 version FW07 and prior versions. WAGO 750-880/xxx-xxx version FW07 and prior versions. WAGO 750-881 version FW07 and prior versions. WAGO 750-831/xxx-xxx version FW07 and prior versions. WAGO 750-882 version FW07 and prior versions. WAGO 750-885/xxx-xxx version FW07 and prior versions. WAGO 750-889 version FW07 and prior versions.

References

Mitigation

Restrict network access to the device.
Do not directly connect the device to the internet.
Disable unused TCP/UDP ports.
Disable web-based management ports 80/443 after the configuration phase

Revision History

Version Date Summary
1 09/30/2020 13:06 Initial revision.
2 05/14/2025 14:28 Fix: removed ia, firmware category, added distribution