CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “wago”

147 vulnerabilities found for “wago”

Page 1 of 8

CVE-2020-12069
HIGH7.8

In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.

pilz / pmc+66
Local
Published Dec 26, 2022
Page 1 of 8
CVE-2021-34566
CRITICAL9.1

In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to crash the iocheck process and write memory resulting in loss of integrity and DoS.

wago / 750-8100_firmware+195
Network
Published Nov 9, 2022
CVE-2021-34567
HIGH8.2

In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to provoke a denial of service and an limited out-of-bounds read.

wago / 750-8100_firmware+195
Network
Published Nov 9, 2022
CVE-2021-34569
CRITICAL9.8

In WAGO I/O-Check Service in multiple products an attacker can send a specially crafted packet containing OS commands to crash the diagnostic tool and write memory.

wago / 750-8100_firmware+195
Network
Published Nov 9, 2022
CVE-2021-34568
HIGH7.5

In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to provoke a denial of service.

wago / 750-8100_firmware+195
Network
Published Nov 9, 2022
CVE-2022-3281
HIGH7.5

WAGO Series PFC100/PFC200, Series Touch Panel 600, Compact Controller CC100 and Edge Controller in multiple versions are prone to a loss of MAC-Address-Filtering after reboot. This may allow an remote attacker to circumvent the reach the network that should be protected by the MAC address filter.

wago / 750-8100_firmware+77
Network
Published Oct 17, 2022
CVE-2021-30186
HIGH7.5

CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow.

wago / 750-893_firmware+28
Network
Published May 25, 2021
CVE-2021-30188
CRITICAL9.8

CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow.

wago / 750-893_firmware+27
Network
Published May 25, 2021
CVE-2021-30194
CRITICAL9.1

CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read.

wago / 750-893_firmware+27
Network
Published May 25, 2021
CVE-2021-30191
HIGH7.5

CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input.

wago / 750-893_firmware+27
Network
Published May 25, 2021
CVE-2021-30193
CRITICAL9.8

CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write.

wago / 750-893_firmware+27
Network
Published May 25, 2021
CVE-2021-30190
CRITICAL9.8

CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control.

wago / 750-893_firmware+27
Network
Published May 25, 2021
CVE-2021-30192
CRITICAL9.8

CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check.

wago / 750-893_firmware+27
Network
Published May 25, 2021
CVE-2021-30189
CRITICAL9.8

CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow.

wago / 750-893_firmware+27
Network
Published May 25, 2021
CVE-2021-30187
MEDIUM5.3

CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command.

wago / 750-893_firmware+27
Local
Published May 25, 2021
CVE-2021-21001
CRITICAL9.1

On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges.

wago / 750-823_firmware+26
Network
Published May 24, 2021
CVE-2021-21000
MEDIUM5.3

On WAGO PFC200 devices in different firmware versions with special crafted packets an attacker with network access to the device could cause a denial of service for the login service of the runtime.

wago / 750-823_firmware+26
Network
Published May 24, 2021
CVE-2020-12516
HIGH7.5

Older firmware versions (FW1 up to FW10) of the WAGO PLC family 750-88x and 750-352 are vulnerable for a special denial of service attack.

wago / 750-352_firmware+9
Network
Published Dec 10, 2020
CVE-2019-10712
CRITICAL9.8

The Web-GUI on WAGO Series 750-88x (750-330, 750-352, 750-829, 750-831, 750-852, 750-880, 750-881, 750-882, 750-884, 750-885, 750-889) and Series 750-87x (750-830, 750-849, 750-871, 750-872, 750-873) devices has undocumented service access.

wago / 750-830_firmware+15
Network
Published May 7, 2019
CVE-2018-16210
MEDIUM6.1

WAGO 750-88X and WAGO 750-89X Ethernet Controller devices, versions 01.09.18(13) and before, have XSS in the SNMP configuration via the webserv/cplcfg/snmp.ssi SNMP_DESC or SNMP_LOC_SNMP_CONT field.

wago / 750-362_firmware+14
Network
Published Oct 12, 2018