Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

164 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)3.3%—Wago 852-303 FirmwareWago 852-1305 FirmwareWago 852-1505 Firmware17/6/201917/6/2026
WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded private keys for the SSH daemon. The fingerprint of the SSH host key from the corresponding SSH daemon matches the embedded private key.
ModificadaCrítica (9.8)2.8%—Wago 750-830 FirmwareWago 750-849 FirmwareWago 750-871 FirmwareWago 750-872 Firmware+127/5/201917/6/2026
The Web-GUI on WAGO Series 750-88x (750-330, 750-352, 750-829, 750-831, 750-852, 750-880, 750-881, 750-882, 750-884, 750-885, 750-889) and Series 750-87x (750-830, 750-849, 750-871, 750-872, 750-873) devices has undocumented service access.
ModificadaAlta (7.5)3.4%—ABB Pm554-tp-eth FirmwarePhoenixcontact ILC 151 ETH FirmwareSchneider-electric Modicon M221 FirmwareSiemens 6es7211-1ae40-0xb0 Firmware+617/4/201917/6/2026
ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network packets.
AnalizadaMedia (6.1)0.95%—Wago 750-362 FirmwareWago 750-363 FirmwareWago 750-823 FirmwareWago 750-832 Firmware+1012/10/201817/6/2026
WAGO 750-88X and WAGO 750-89X Ethernet Controller devices, versions 01.09.18(13) and before, have XSS in the SNMP configuration via the webserv/cplcfg/snmp.ssi SNMP_DESC or SNMP_LOC_SNMP_CONT field.
ModificadaMedia (5.4)5.2%💥 ExploitWago 762-3000 FirmwareWago 762-3001 FirmwareWago 762-3002 FirmwareWago 762-3003 Firmware12/7/201817/6/2026
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability can be exploited by authenticated and unauthenticated users by sending special crafted requests to the web server allowing injecting code within the WBM. The code will be rendered and/or executed…
ModificadaAlta (8.8)30%💥 ExploitWago 762-3000 FirmwareWago 762-3001 FirmwareWago 762-3002 FirmwareWago 762-3003 Firmware12/7/201817/6/2026
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability allows an authenticated user to upload arbitrary files to the file system with the permissions of the web server.
ModificadaMedia (6.5)7.8%💥 ExploitWago 762-3000 FirmwareWago 762-3001 FirmwareWago 762-3002 FirmwareWago 762-3003 Firmware12/7/201817/6/2026
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. Weak permissions allow an authenticated user to overwrite critical files by abusing the unrestricted file upload in the WBM.
ModificadaMedia (5.3)3.7%—Wago 750-880 FirmwareWago 750-881 FirmwareWago 750-852 FirmwareWago 750-882 Firmware+43/4/201817/6/2026
Wago 750 Series PLCs with firmware version 10 and prior include a remote attack may take advantage of an improper implementation of the 3 way handshake during a TCP connection affecting the communications with commission and service tools. Specially crafted packets may also be sent to Port 2455/TCP/IP, used in Codesys…
ModificadaCrítica (9.8)2.7%—Wago Pfc200 Firmware13/2/201817/6/2026
An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An attacker can execute different unauthenticated remote operations because of the CoDeSys Runtime application, which is available via network by default on Port 2455. An attacker could execute some…
ModificadaCrítica (9.8)3.5%—Wago 750-849 FirmwareWago 758-870 Firmware22/8/201717/6/2026
WAGO IO 750-849 01.01.27 and WAGO IO 750-881 01.02.05 do not contain privilege separation.
ModificadaCrítica (9.8)2.9%—Wago 750-849 FirmwareWago 750-881 FirmwareWago 758-870 Firmware22/8/201717/6/2026
WAGO IO 750-849 01.01.27 and 01.02.05, WAGO IO 750-881, and WAGO IO 758-870 have weak credential management.
ModificadaCrítica (9.1)2.1%—Wago Pfc200 FirmwareWago 750-xxxx Series FirmwareWago 758-xxxx Series Firmware13/2/201717/6/2026
An issue was discovered in WAGO 750-8202/PFC200 prior to FW04 (released August 2015), WAGO 750-881 prior to FW09 (released August 2016), and WAGO 0758-0874-0000-0111. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to edit and to view settings without authenticating.
ModificadaAlta (10)3.2%—Wago I/O System 758 Industrial PC Device7/9/201216/6/2026
The Linux Console on the WAGO I/O System 758 model 758-870, 758-874, 758-875, and 758-876 Industrial PC (IPC) devices has a default password of wago for the (1) root and (2) admin accounts, (3) a default password of user for the user account, and (4) a default password of guest for the guest account, which makes it…
ModificadaAlta (10)3.2%—Wago I/O System 758 Industrial PC Device7/9/201216/6/2026
WAGO I/O System 758 model 758-870, 758-874, 758-875, and 758-876 Industrial PC (IPC) devices have default passwords for unspecified Web Based Management accounts, which makes it easier for remote attackers to obtain administrative access via a TCP session.
Orbitaley — Vulnerabilidades