Back to overview

WAGO: Multiple Devices are affected by a Vulnerability in BACnet IP Stack

VDE-2025-102
Last update
10/01/2026 12:00
Published at
10/01/2026 12:00
Vendor(s)
WAGO GmbH & Co. KG
External ID
VDE-2025-102
CSAF Document

Summary

Multiple WAGO devices are affected by a vulnerability in the dynamic creation of BACnet File Objects. The object name is used as a file path without sufficient validation and is not restricted to the intended directory, so relative paths can be used to reach files elsewhere in the file system.

Impact

An attacker can read or overwrite arbitrary files without authentication via BACnet File Object indirect addressing. This may expose sensitive data (e.g., password files) and enable full system compromise or service disruption.

Affected Product(s)

Model no. Product name Affected versions
0750-811?-????-???? 0750-811x-xxxx-xxxx wago_os_linux <4.8.9 (FW30), custom wago_os_linux <4.8.9 (70)
0750-821?-????-???? 0750-821x-xxx-xxx custom wago_os_linux <4.8.9 (70), wago_os_linux <4.8.9 (FW30)
0751-9?01 0751-9x01 wago_os_linux <4.8.9 (FW30), custom wago_os_linux <4.8.9 (70)
0752-8303-8000-0002 0752-8303-8000-0002 custom wago_os_linux <4.8.9 (70), wago_os_linux <4.8.9 (FW30)
0762-340? 0762-340x custom wago_os_linux <4.8.9 (70), wago_os_linux <4.8.9 (FW30)
0762-420?-8000-000? 0762-420x-8000-000x wago_os_linux <4.8.9 (FW30), custom wago_os_linux <4.8.9 (70)
0762-430?-8000-000? 0762-430x-8000-000x wago_os_linux <4.8.9 (FW30), custom wago_os_linux <4.8.9 (70)
0762-520?-8000-000? 0762-520x-8000-000x wago_os_linux <4.8.9 (FW30), custom wago_os_linux <4.8.9 (70)
0762-530?-8000-000? 0762-530x-8000-000x wago_os_linux <4.8.9 (FW30), custom wago_os_linux <4.8.9 (70)
0762-620?-8000-000? 0762-620x-8000-000x wago_os_linux <4.8.9 (FW30), custom wago_os_linux <4.8.9 (70)
0762-630?-8000-000? 0762-630x-8000-000x wago_os_linux <4.8.9 (FW30), custom wago_os_linux <4.8.9 (70)

Vulnerabilities

Expand / Collapse all

Published
10/01/2026 08:42
Weakness
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Summary

The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise.

References

Remediation

Update to Firmware version 4.8.9 (FW30) or higher. For the latest custom Firmware please contact the WAGO support.

Acknowledgments

WAGO GmbH & Co. KG thanks the following parties for their efforts:

Revision History

Version Date Summary
1.0.0 10/01/2026 12:00 Release version.