CVE-2023-3379: Wago Compact Controller 100 Firmware

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges.

Affected products

  • Wago Compact Controller 100 Firmware: up to and including 25
  • Wago Edge Controller Firmware: up to and including 25
  • Wago PFC100 Firmware: before 22 (fixed in 22); version 22 only
  • Wago PFC200 Firmware: before 22 (fixed in 22); version 22 only; version 23 only; version 24 only
  • Wago Touch Panel 600 Advanced Firmware: up to and including 25
  • Wago Touch Panel 600 Marine Firmware: up to and including 25
  • Wago Touch Panel 600 Standard Firmware: up to and including 25

Published 2023-11-20. Last modified 2026-06-17.