CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

wago

750-8202_firmware

27 known vulnerabilities · sorted by CVSS score

CVE-2021-30193
CRITICAL9.8

CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write.

wago / 750-893_firmware+27
Network
Published May 25, 2021
Page 1 of 2
CVE-2021-30189
CRITICAL9.8

CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow.

wago / 750-893_firmware+27
Network
Published May 25, 2021
CVE-2021-30192
CRITICAL9.8

CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check.

wago / 750-893_firmware+27
Network
Published May 25, 2021
CVE-2021-34569
CRITICAL9.8

In WAGO I/O-Check Service in multiple products an attacker can send a specially crafted packet containing OS commands to crash the diagnostic tool and write memory.

wago / 750-8100_firmware+195
Network
Published Nov 9, 2022
CVE-2021-30188
CRITICAL9.8

CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow.

wago / 750-893_firmware+27
Network
Published May 25, 2021
CVE-2021-30190
CRITICAL9.8

CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control.

wago / 750-893_firmware+27
Network
Published May 25, 2021
CVE-2021-34566
CRITICAL9.1

In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to crash the iocheck process and write memory resulting in loss of integrity and DoS.

wago / 750-8100_firmware+195
Network
Published Nov 9, 2022
CVE-2021-21001
CRITICAL9.1

On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges.

wago / 750-823_firmware+26
Network
Published May 24, 2021
CVE-2021-30194
CRITICAL9.1

CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read.

wago / 750-893_firmware+27
Network
Published May 25, 2021
CVE-2021-34584
CRITICAL9.1

Crafted web server requests can be utilised to read partial stack or heap memory or may trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22.

wago / 750-823_firmware+27
Network
Published Oct 26, 2021
CVE-2021-34567
HIGH8.2

In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to provoke a denial of service and an limited out-of-bounds read.

wago / 750-8100_firmware+195
Network
Published Nov 9, 2022
CVE-2021-34595
HIGH8.1

A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or local memory overwrite.

wago / 750-823_firmware+29
Network
Published Oct 26, 2021
CVE-2020-12069
HIGH7.8

In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.

pilz / pmc+66
Local
Published Dec 26, 2022
CVE-2021-30186
HIGH7.5

CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow.

wago / 750-893_firmware+28
Network
Published May 25, 2021
CVE-2021-34586
HIGH7.5

In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests may cause a Null pointer dereference in the CODESYS web server and may result in a denial-of-service condition.

wago / 750-823_firmware+27
Network
Published Oct 26, 2021
CVE-2021-34568
HIGH7.5

In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to provoke a denial of service.

wago / 750-8100_firmware+195
Network
Published Nov 9, 2022
CVE-2021-30191
HIGH7.5

CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input.

wago / 750-893_firmware+27
Network
Published May 25, 2021
CVE-2021-34583
HIGH7.5

Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22.

wago / 750-8214_firmware+27
Network
Published Oct 26, 2021
CVE-2021-34585
HIGH7.5

In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under all conditions, a pointer dereference with an invalid address can occur. This leads to a denial of service situation.

wago / 750-823_firmware+27
Network
Published Oct 26, 2021
CVE-2021-34593
HIGH7.5

In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory may be leaked, or further communication clients may be blocked from accessing the PLC.

wago / 750-8202_firmware+14
Network
Published Oct 26, 2021