← Back to home
ICSA-16-357-02  ·  Published 2025-06-05  ·  View on CISA ICS-CERT ↗

WAGO Ethernet Web-based Management Authentication Bypass Vulnerability

CVSS 9.1 CRITICAL

CVEs (1)

Remediations

  • WAGO recommends the following use conditions for Ethernet devices:
  • If not otherwise specified, Ethernet devices are intended for use on local networks. Users should note the following when using Ethernet devices:
  • Do not connect control components and control networks to an open network such as the Internet or an office network. WAGO recommends putting control components and control networks behind a firewall.
  • Limit physical and electronic access to all automation components to authorized personnel only.
  • Change the default passwords before first use. This will reduce the risk of unauthorized access to systems. Regularly change passwords. This will reduce the risk of unauthorized access to systems.
  • If remote access to control components and control networks is required, use a Virtual Private Network (VPN).
  • Regularly perform threat analyses. Check whether the measures taken meet company security requirements.
  • Use “defense-in-depth” mechanisms in the system’s security configuration to restrict the access to and control of individual products and networks.

Affected Vendors

WAGO

Affected Products (3)

WAGO · WAGO 750-8202/PFC200 <FW04
WAGO · WAGO 750-881 <FW09
WAGO · WAGO 0758-0874-0000-0111 vers:all/*

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more