CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

wago

750-891_firmware

24 known vulnerabilities · sorted by CVSS score

CVE-2021-34578
CRITICAL9.8

This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAGO PLCs in firmware versions up to FW07.

wago / 750-890\/040-000_firmware+11
Network
Published Aug 31, 2021
Page 1 of 2
CVE-2021-30189
CRITICAL9.8

CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow.

wago / 750-893_firmware+27
Network
Published May 25, 2021
CVE-2021-30188
CRITICAL9.8

CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow.

wago / 750-893_firmware+27
Network
Published May 25, 2021
CVE-2021-30192
CRITICAL9.8

CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check.

wago / 750-893_firmware+27
Network
Published May 25, 2021
CVE-2021-30190
CRITICAL9.8

CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control.

wago / 750-893_firmware+27
Network
Published May 25, 2021
CVE-2021-30193
CRITICAL9.8

CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write.

wago / 750-893_firmware+27
Network
Published May 25, 2021
CVE-2020-12506
CRITICAL9.1

Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attacker to change the settings of the devices by sending specifically constructed requests without authentication This issue affects: WAGO 750-362, WAGO 750-363, WAGO 750-823, WAGO 750-832/xxx-xxx, WAGO 750-862, WAGO 750-891, WAGO 750-890/xxx-xxx in versions FW03 and prior versions.

wago / 750-362_firmware+6
Network
Published Sep 30, 2020
CVE-2021-21001
CRITICAL9.1

On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges.

wago / 750-823_firmware+26
Network
Published May 24, 2021
CVE-2021-30194
CRITICAL9.1

CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read.

wago / 750-893_firmware+27
Network
Published May 25, 2021
CVE-2021-34584
CRITICAL9.1

Crafted web server requests can be utilised to read partial stack or heap memory or may trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22.

wago / 750-823_firmware+27
Network
Published Oct 26, 2021
CVE-2021-34595
HIGH8.1

A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or local memory overwrite.

wago / 750-823_firmware+29
Network
Published Oct 26, 2021
CVE-2021-34585
HIGH7.5

In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under all conditions, a pointer dereference with an invalid address can occur. This leads to a denial of service situation.

wago / 750-823_firmware+27
Network
Published Oct 26, 2021
CVE-2021-30186
HIGH7.5

CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow.

wago / 750-893_firmware+28
Network
Published May 25, 2021
CVE-2021-34586
HIGH7.5

In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests may cause a Null pointer dereference in the CODESYS web server and may result in a denial-of-service condition.

wago / 750-823_firmware+27
Network
Published Oct 26, 2021
CVE-2023-1150
HIGH7.5

Uncontrolled resource consumption in Series WAGO 750-3x/-8x products may allow an unauthenticated remote attacker to DoS the MODBUS server with specially crafted packets.

wago / 750-363\/040-000_firmware+17
Network
Published Jun 26, 2023
CVE-2021-30191
HIGH7.5

CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input.

wago / 750-893_firmware+27
Network
Published May 25, 2021
CVE-2021-30195
HIGH7.5

CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation.

wago / 750-893_firmware+28
Network
Published May 25, 2021
CVE-2021-34583
HIGH7.5

Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22.

wago / 750-8214_firmware+27
Network
Published Oct 26, 2021
CVE-2021-34596
MEDIUM6.5

A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition.

wago / 750-823_firmware+29
Network
Published Oct 26, 2021
CVE-2018-16210
MEDIUM6.1

WAGO 750-88X and WAGO 750-89X Ethernet Controller devices, versions 01.09.18(13) and before, have XSS in the SNMP configuration via the webserv/cplcfg/snmp.ssi SNMP_DESC or SNMP_LOC_SNMP_CONT field.

wago / 750-362_firmware+14
Network
Published Oct 12, 2018