logo

Team82 Uncovers RCE Vulnerability in WAGO Controller Firmware

ID: b4e6a4cc-4691-52a1-9976-90dbd12f42a1

STIX ID: report--b4e6a4cc-4691-52a1-9976-90dbd12f42a1

Feed Name: Claroty Team82

Threat Score
70/100

Date Published: 2022-11-30

Date Updated: 2026-04-17

Author: Uri Katz

...
...

**Executive summary:** Claroty Team82 publicly disclosed CVE-2020-12522, a critical (CVSS 10.0) unauthenticated remote command-injection vulnerability in the WAGO I/O-Check (iocheckd) management protocol on TCP/6626 affecting WAGO PFC100/PFC200 and Touch Panel firmware versions up to FW10; exploitation allows remote root code execution via a single crafted TCP packet. The vendor fixed the issue in FW11 (Dec 2017); recommended mitigations include firmware upgrade, disabling the I/O-Check service, network segmentation/ACLs, and the report includes a Snort rule for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.