CVE-2018-8836: Wago 750-829 Firmware

Medium severity, CVSS 5.3. EPSS: 3.7% chance of exploitation in the next 30 days.

Wago 750 Series PLCs with firmware version 10 and prior include a remote attack may take advantage of an improper implementation of the 3 way handshake during a TCP connection affecting the communications with commission and service tools. Specially crafted packets may also be sent to Port 2455/TCP/IP, used in Codesys management software, which may result in a denial-of-service condition of communications with commissioning and service tools.

Affected products

  • Wago 750-829 Firmware: up to and including 10
  • Wago 750-831 Firmware: up to and including 10
  • Wago 750-852 Firmware: up to and including 10
  • Wago 750-880 Firmware: up to and including 10
  • Wago 750-881 Firmware: up to and including 10
  • Wago 750-882 Firmware: up to and including 10
  • Wago 750-885 Firmware: up to and including 10
  • Wago 750-889 Firmware: up to and including 10

Published 2018-04-03. Last modified 2026-06-17.