CVE-2025-25264: Wago CC100 0751-9x01

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An unauthenticated remote attacker can trick an admin to visit a website containing malicious java script code. The current overly permissive CORS policy allows the attacker to obtain any files from the file system.

Affected products

  • Wago CC100 0751-9x01: from 0.0.0, before 04.07.01 (FW29) (fixed in 04.07.01 (FW29)); from 0.0.0, before 04.07.01 (70 (fixed in 04.07.01 (70)
  • Wago Edge Controller 0752-8303/8000-0002: from 0.0.0, before 04.07.01 (FW29) (fixed in 04.07.01 (FW29)); from 0.0.0, before 04.07.01 (70) (fixed in 04.07.01 (70))
  • Wago PFC100 g1 0750-810x/xxxx-Xxxx
  • Wago PFC100 g2 0750-811x-Xxxx-Xxxx: from 0.0.0, before 04.07.01 (70) (fixed in 04.07.01 (70))
  • Wago PFC200 g1 750-820x-Xxx-Xxx
  • Wago PFC200 g2 750-821x-Xxx-Xxx: from 0.0.0, before 04.07.01 (FW29) (fixed in 04.07.01 (FW29)); from 0.0.0, before 04.07.01 (70) (fixed in 04.07.01 (70))
  • Wago TP600 0762-420x/8000-000x: from 0.0.0, before 04.07.01 (FW29) (fixed in 04.07.01 (FW29)); from 0.0.0, before 04.07.01 (70) (fixed in 04.07.01 (70))
  • Wago TP600 0762-430x/8000-000x: from 0.0.0, before 04.07.01 (FW29) (fixed in 04.07.01 (FW29)); from 0.0.0, before 04.07.01 (70) (fixed in 04.07.01 (70))
  • Wago TP600 0762-520x/8000-000x: from 0.0.0, before 04.07.01 (FW29) (fixed in 04.07.01 (FW29)); from 0.0.0, before 04.07.01 (70) (fixed in 04.07.01 (70))
  • Wago TP600 0762-530x/8000-000x: from 0.0.0, before 04.07.01 (FW29) (fixed in 04.07.01 (FW29)); from 0.0.0, before 04.07.01 (70) (fixed in 04.07.01 (70))
  • Wago TP600 0762-620x/8000-000x: from 0.0.0, before 04.07.01 (FW29) (fixed in 04.07.01 (FW29)); from 0.0.0, before 04.07.01 (70) (fixed in 04.07.01 (70))
  • Wago TP600 0762-630x/8000-000x: from 0.0.0, before 04.07.01 (FW29) (fixed in 04.07.01 (FW29)); from 0.0.0, before 04.07.01 (70) (fixed in 04.07.01 (70))

Published 2025-06-16. Last modified 2026-06-17.