Description
User credentials are stored using AES‑ECB encryption with a hardcoded key. An unauthenticated remote attacker obtaining the configuration file can decrypt and recover plaintext usernames and passwords, especially when combined with the authentication bypass.
Scores
CVSS v3
9.8
EPSS
0.0006
EPSS Percentile
20.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-321
Status
published
Products (4)
WAGO/0852-1322
0.0.0 - 2.64
WAGO/0852-1322
2.64
WAGO/0852-1328
0.0.0 - 2.64
WAGO/0852-1328
2.64
Published
Feb 09, 2026
Tracked Since
Feb 18, 2026