CVE-2023-1698: Wago Compact Controller 100 Firmware

Critical severity, CVSS 9.8. EPSS: 81.9% chance of exploitation in the next 30 days.

In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.

Affected products

  • Wago Compact Controller 100 Firmware: from 20, up to and including 23
  • Wago Edge Controller Firmware: version 22 only
  • Wago PFC100 Firmware: from 20, up to and including 23
  • Wago PFC200 Firmware: from 20, up to and including 23
  • Wago Touch Panel 600 Advanced Firmware: version 22 only
  • Wago Touch Panel 600 Marine Firmware: version 22 only
  • Wago Touch Panel 600 Standard Firmware: version 22 only

Published 2023-05-15. Last modified 2026-06-17.