Summary
Multiple WAGO devices are affected by a vulnerability in the dynamic creation of BACnet File Objects. The object name is used as a file path without sufficient validation and is not restricted to the intended directory, so relative paths can be used to reach files elsewhere in the file system.
Impact
An attacker can read or overwrite arbitrary files without authentication via BACnet File Object indirect addressing. This may expose sensitive data (e.g., password files) and enable full system compromise or service disruption.
Affected Product(s)
| Model no. | Product name | Affected versions |
|---|---|---|
| 0750-811?-????-???? | 0750-811x-xxxx-xxxx | wago_os_linux <4.8.9 (FW30), custom wago_os_linux <4.8.9 (70) |
| 0750-821?-????-???? | 0750-821x-xxx-xxx | custom wago_os_linux <4.8.9 (70), wago_os_linux <4.8.9 (FW30) |
| 0751-9?01 | 0751-9x01 | wago_os_linux <4.8.9 (FW30), custom wago_os_linux <4.8.9 (70) |
| 0752-8303-8000-0002 | 0752-8303-8000-0002 | custom wago_os_linux <4.8.9 (70), wago_os_linux <4.8.9 (FW30) |
| 0762-340? | 0762-340x | custom wago_os_linux <4.8.9 (70), wago_os_linux <4.8.9 (FW30) |
| 0762-420?-8000-000? | 0762-420x-8000-000x | wago_os_linux <4.8.9 (FW30), custom wago_os_linux <4.8.9 (70) |
| 0762-430?-8000-000? | 0762-430x-8000-000x | wago_os_linux <4.8.9 (FW30), custom wago_os_linux <4.8.9 (70) |
| 0762-520?-8000-000? | 0762-520x-8000-000x | wago_os_linux <4.8.9 (FW30), custom wago_os_linux <4.8.9 (70) |
| 0762-530?-8000-000? | 0762-530x-8000-000x | wago_os_linux <4.8.9 (FW30), custom wago_os_linux <4.8.9 (70) |
| 0762-620?-8000-000? | 0762-620x-8000-000x | wago_os_linux <4.8.9 (FW30), custom wago_os_linux <4.8.9 (70) |
| 0762-630?-8000-000? | 0762-630x-8000-000x | wago_os_linux <4.8.9 (FW30), custom wago_os_linux <4.8.9 (70) |
Vulnerabilities
Expand / Collapse allThe object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise.
Remediation
Update to Firmware version 4.8.9 (FW30) or higher. For the latest custom Firmware please contact the WAGO support.
Acknowledgments
WAGO GmbH & Co. KG thanks the following parties for their efforts:
- CERT@VDE for coordination (see https://certvde.com )
Revision History
| Version | Date | Summary |
|---|---|---|
| 1.0.0 | 01.10.2026 12:00 | Release version. |