CVE-2025-0101: Wago CC100 0751-9x01
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
A low privileged user can set the date of the devices to the 19th of January 2038 an therefore exceed the 32-Bit time limit. This causes some functions to work unexpected or stop working at all. Both during runtime and after a restart.
Affected products
- Wago CC100 0751-9x01: before 04.07.01 (fixed in 04.07.01)
- Wago PFC100 g1 0750-810x/xxxx-Xxxx: before 3.10.11 (fixed in 3.10.11); before 03.10.11 (fixed in 03.10.11)
- Wago PFC100 g2 0750-811x-Xxxx-Xxxx: before 04.07.01 (fixed in 04.07.01)
- Wago PFC200 g1 750-820x-Xxx-Xxx: before 3.10.11 (fixed in 3.10.11); before 03.10.11 (fixed in 03.10.11)
- Wago PFC200 g2 750-821x-Xxx-Xxx: before 04.07.01 (fixed in 04.07.01)
- Wago TP600 0762-420x/8000-000x: before 04.07.01 (fixed in 04.07.01)
- Wago TP600 0762-430x/8000-000x: before 04.07.01 (fixed in 04.07.01)
- Wago TP600 0762-520x/8000-000x: before 04.07.01 (fixed in 04.07.01)
- Wago TP600 0762-530x/8000-000x: before 04.07.01 (fixed in 04.07.01)
- Wago TP600 0762-620x/8000-000x: before 04.07.01 (fixed in 04.07.01)
- Wago TP600 0762-630x/8000-000x: before 04.07.01 (fixed in 04.07.01)
- Wago Wago CC100 0751-9x01: before 04.07.01 (fixed in 04.07.01)
- Wago Wago Edge Controller 0752-8303/8000-0002: before 04.07.01 (fixed in 04.07.01)
Published 2025-04-16. Last modified 2026-06-17.