wago security advisories
5 threat alerts tracking vulnerabilities and security advisories that affect wago products.
Vulnios monitors wago CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent wago security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2025-41730 — wago — 0852-1328_firmware, 0852-1328
An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_account() function to write arbitrary data into fixed-size stack buffers which leads to full device compromise.
criticalCVE-2025-41730Critical Vulnerability: CVE-2025-41732 — wago — 0852-1328_firmware, 0852-1328
An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_cookie() function to write arbitrary data into fixed-size stack buffers which leads to full device compromise.
criticalCVE-2025-41732Critical Vulnerability: CVE-2015-6472 — wago — 750-849_firmware, 750-849
WAGO IO 750-849 01.01.27 and 01.02.05, WAGO IO 750-881, and WAGO IO 758-870 have weak credential management.
criticalCVE-2015-6472Critical Vulnerability: CVE-2015-6473 — wago — 750-849_firmware, 750-849
WAGO IO 750-849 01.01.27 and WAGO IO 750-881 01.02.05 do not contain privilege separation.
criticalCVE-2015-6473Critical Vulnerability: CVE-2016-9362 — wago — pfc200_firmware, pfc200
An issue was discovered in WAGO 750-8202/PFC200 prior to FW04 (released August 2015), WAGO 750-881 prior to FW09 (released August 2016), and WAGO 0758-0874-0000-0111. By accessing a specific uniform r
criticalCVE-2016-9362
Track wago exposure across your environment
Vulnios automatically cross-references your asset inventory against new wago CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan