CVE-2023-4089: Wago Compact Controller 100 Firmware

Low severity, CVSS 2.7. EPSS: 0.5% chance of exploitation in the next 30 days.

On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected.

Affected products

  • Wago Compact Controller 100 Firmware: from 19, up to and including 26
  • Wago Edge Controller Firmware: from 18, up to and including 26
  • Wago PFC100 Firmware: from 16, up to and including 26
  • Wago PFC200 Firmware: from 16, up to and including 26
  • Wago Touch Panel 600 Advanced Firmware: from 16, up to and including 26
  • Wago Touch Panel 600 Marine Firmware: from 16, up to and including 26
  • Wago Touch Panel 600 Standard Firmware: from 16, up to and including 26

Published 2023-10-17. Last modified 2026-06-17.