WAGO has 3 CVEs on record between 2025 and 2026. 1 was published in the last 90 days. The median CVSS is 9.8 (critical), with 3 rated critical. Most affected products: 0852-1328_firmware (2), 0751-9x01 (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 9.8
- Publish → KEV
- —
- Last 90 days
- 1 prev 0
Worst active — by depth score
CVE-2025-41753Critical· 9.8The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation54CVE-2025-41732Critical· 9.8An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_cookie() function to write arbitrary data into fixed-size stack buffers which leads to full device compromise.54CVE-2025-41730Critical· 9.8An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_account() function to write arbitrary data into fixed-size stack buffers which leads to full device compromise.54
WAGO vulnerabilities
CVEs affecting WAGO, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2025-41753Critical· 9.8The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation
The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse ou…
CVE-2025-41732Critical· 9.8An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_cookie() function to write arbitrary data into fixed-size stack buffers which leads to full device compromise.
An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_cookie() function to write arbitrary data into fixed-size stack buffers which leads to full device compromise.
CVE-2025-41730Critical· 9.8An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_account() function to write arbitrary data into fixed-size stack buffers which leads to full device compromise.
An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_account() function to write arbitrary data into fixed-size stack buffers which leads to full device compromise.