CVE-2022-45138: Wago 751-9301 Firmware
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read and set several device parameters that can lead to full compromise of the device.
Affected products
- Wago 751-9301 Firmware: from 16, before 22 (fixed in 22); version 22 only; version 23 only
- Wago 752-8303/8000-002 Firmware: from 18, before 22 (fixed in 22); version 22 only; version 23 only
- Wago PFC100 Firmware: from 16, before 22 (fixed in 22); version 22 only; version 23 only
- Wago PFC200 Firmware: from 16, before 22 (fixed in 22); version 22 only; version 23 only
- Wago Touch Panel 600 Advanced Firmware: from 16, before 22 (fixed in 22); version 22 only; version 23 only
- Wago Touch Panel 600 Marine Firmware: from 16, before 22 (fixed in 22); version 22 only; version 23 only
- Wago Touch Panel 600 Standard Firmware: from 16, before 22 (fixed in 22); version 22 only; version 23 only
Published 2023-02-27. Last modified 2026-06-17.