CVE-2024-1490: Wago CC100 0751-9x01

High severity, CVSS 7.2. EPSS: 0.7% chance of exploitation in the next 30 days.

An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management interface of a WAGO PLC. If user-defined scripts are permitted, OpenVPN may allow the execution of arbitrary shell commands enabling the attacker to run arbitrary commands on the device.

Affected products

  • Wago CC100 0751-9x01: from 0.0.0, up to and including 4.5.10
  • Wago Edge Controller 0752-8303-8000-0002: from 0.0.0, up to and including 4.5.10
  • Wago PFC100 g1 0750-810-Xxxx-Xxxx: from 0.0.0, up to and including 3.10.10
  • Wago PFC100 g2 0750-811x-Xxxx-Xxxx: from 0.0.0, up to and including 4.5.10
  • Wago PFC200 g1 750-820x-Xxxx-Xxxx: from 0.0.0, up to and including 3.10.10
  • Wago PFC200 g2 750-821x-Xxxx-Xxxx: from 0.0.0, up to and including 4.5.10
  • Wago TP600 0762-420x-8000-000x
  • Wago TP600 0762-430x-8000-000x: from 0.0.0, up to and including 4.5.10
  • Wago TP600 0762-520x-8000-000x: from 0.0.0, up to and including 4.5.10
  • Wago TP600 0762-530x-8000-000x: from 0.0.0, up to and including 4.5.10
  • Wago TP600 0762-620x-8000-000x: version 0.0.0 only
  • Wago TP600 0762-630x-8000-000x: from 0.0.0, up to and including 4.5.10
  • Wago WP400 0762-340x: from 0.0.0, up to and including 4.5.10

Published 2026-04-09. Last modified 2026-06-17.