CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

wago

750-893_firmware

22 known vulnerabilities · sorted by CVSS score

CVE-2021-34578
CRITICAL9.8

This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAGO PLCs in firmware versions up to FW07.

wago / 750-890\/040-000_firmware+11
Network
Published Aug 31, 2021
Page 1 of 2
CVE-2021-30188
CRITICAL9.8

CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow.

wago / 750-893_firmware+27
Network
Published May 25, 2021
CVE-2021-30189
CRITICAL9.8

CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow.

wago / 750-893_firmware+27
Network
Published May 25, 2021
CVE-2021-30192
CRITICAL9.8

CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check.

wago / 750-893_firmware+27
Network
Published May 25, 2021
CVE-2021-30190
CRITICAL9.8

CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control.

wago / 750-893_firmware+27
Network
Published May 25, 2021
CVE-2021-30193
CRITICAL9.8

CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write.

wago / 750-893_firmware+27
Network
Published May 25, 2021
CVE-2021-34584
CRITICAL9.1

Crafted web server requests can be utilised to read partial stack or heap memory or may trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22.

wago / 750-823_firmware+27
Network
Published Oct 26, 2021
CVE-2021-30194
CRITICAL9.1

CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read.

wago / 750-893_firmware+27
Network
Published May 25, 2021
CVE-2021-21001
CRITICAL9.1

On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges.

wago / 750-823_firmware+26
Network
Published May 24, 2021
CVE-2021-34595
HIGH8.1

A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or local memory overwrite.

wago / 750-823_firmware+29
Network
Published Oct 26, 2021
CVE-2021-30186
HIGH7.5

CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow.

wago / 750-893_firmware+28
Network
Published May 25, 2021
CVE-2021-30195
HIGH7.5

CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation.

wago / 750-893_firmware+28
Network
Published May 25, 2021
CVE-2023-1150
HIGH7.5

Uncontrolled resource consumption in Series WAGO 750-3x/-8x products may allow an unauthenticated remote attacker to DoS the MODBUS server with specially crafted packets.

wago / 750-363\/040-000_firmware+17
Network
Published Jun 26, 2023
CVE-2021-34586
HIGH7.5

In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests may cause a Null pointer dereference in the CODESYS web server and may result in a denial-of-service condition.

wago / 750-823_firmware+27
Network
Published Oct 26, 2021
CVE-2021-30191
HIGH7.5

CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input.

wago / 750-893_firmware+27
Network
Published May 25, 2021
CVE-2021-34583
HIGH7.5

Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22.

wago / 750-8214_firmware+27
Network
Published Oct 26, 2021
CVE-2021-34585
HIGH7.5

In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under all conditions, a pointer dereference with an invalid address can occur. This leads to a denial of service situation.

wago / 750-823_firmware+27
Network
Published Oct 26, 2021
CVE-2021-34596
MEDIUM6.5

A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition.

wago / 750-823_firmware+29
Network
Published Oct 26, 2021
CVE-2021-21000
MEDIUM5.3

On WAGO PFC200 devices in different firmware versions with special crafted packets an attacker with network access to the device could cause a denial of service for the login service of the runtime.

wago / 750-823_firmware+26
Network
Published May 24, 2021
CVE-2021-30187
MEDIUM5.3

CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command.

wago / 750-893_firmware+27
Local
Published May 25, 2021