CVE-2022-45140

CRITICAL

WAGO PFC100/PFC200/751-9301/752-8303/TP600 Firmware 16-21 - Unauthenticated RCE via Arbitrary File Write

Title source: llm
STIX 2.1

Description

The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0107
EPSS Percentile 60.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-306
Status published
Products (21)
wago/751-9301_firmware 22
wago/751-9301_firmware 23
wago/751-9301_firmware 16 - 22
wago/752-8303\/8000-002_firmware 22
wago/752-8303\/8000-002_firmware 23
wago/752-8303\/8000-002_firmware 18 - 22
wago/pfc100_firmware 22
wago/pfc100_firmware 23
wago/pfc100_firmware 16 - 22
wago/pfc200_firmware 22
... and 11 more
Published Feb 27, 2023
Tracked Since Feb 18, 2026