logo

Factory Flaw: Critical WAGO Switch Vulnerabilities (CVSS 9.8) Allow Remote Takeover

ID: f60b8168-394c-5c61-b34e-126787074f60

STIX ID: report--f60b8168-394c-5c61-b34e-126787074f60

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-02-11

Date Updated: 2026-04-23

Author: Ddos

...
...

CERT@VDE warns that WAGO 852-series industrial managed switches (models 8052-1322 and 0852-1328, firmware ≤2.64) contain multiple critical vulnerabilities: CVE-2026-22906 (stored credentials encrypted with AES-ECB using a hardcoded key allowing plaintext recovery), CVE-2026-22904 and CVE-2026-22903 (stack buffer overflows via oversized TRACKID/SESSIONID cookies enabling crashes or potential RCE), and CVE-2026-22905 (authentication bypass via path traversal). These unauthenticated, remotely-triggerable flaws could permit attackers to obtain administrative credentials, execute arbitrary code, crash the web service, and take control of OT network switches if exploited.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.