CVE-2025-25265: Wago CC100 0751-9x01
Medium severity, CVSS 4.9. EPSS: 0.5% chance of exploitation in the next 30 days.
A web application for configuring the controller is accessible at a specific path. It contains an endpoint that allows a high privileged remote attacker to read files from the system’s file structure.
Affected products
- Wago CC100 0751-9x01: from 0.0.0, before 04.07.01 (70) (fixed in 04.07.01 (70))
- Wago Edge Controller 0752-8303/8000-0002: from 0.0.0, before 04.07.01 (FW29) (fixed in 04.07.01 (FW29)); from 0.0.0, before 04.07.01 (70) (fixed in 04.07.01 (70))
- Wago PFC100 g1 0750-810x/xxxx-Xxxx
- Wago PFC100 g2 0750-811x-Xxxx-Xxxx: from 0.0.0, before 04.07.01 (FW29) (fixed in 04.07.01 (FW29)); from 0.0.0, before 04.07.01 (70) (fixed in 04.07.01 (70))
- Wago PFC200 g1 750-820x-Xxx-Xxx
- Wago PFC200 g2 750-821x-Xxx-Xxx: from 0.0.0, before 04.07.01 (FW29) (fixed in 04.07.01 (FW29)); from 0.0.0, before 04.07.01 (70) (fixed in 04.07.01 (70))
- Wago TP600 0762-420x/8000-000x: from 0.0.0, before 04.07.01 (FW29) (fixed in 04.07.01 (FW29)); from 0.0.0, before 04.07.01 (70) (fixed in 04.07.01 (70))
- Wago TP600 0762-430x/8000-000x: from 0.0.0, before 04.07.01 (FW29) (fixed in 04.07.01 (FW29)); from 0.0.0, before 04.07.01 (70) (fixed in 04.07.01 (70))
- Wago TP600 0762-520x/8000-000x: from 0.0.0, before 04.07.01 (FW29) (fixed in 04.07.01 (FW29)); from 0.0.0, before 04.07.01 (70) (fixed in 04.07.01 (70))
- Wago TP600 0762-530x/8000-000x: from 0.0.0, before 04.07.01 (FW29) (fixed in 04.07.01 (FW29)); from 0.0.0, before 04.07.01 (70) (fixed in 04.07.01 (70))
- Wago TP600 0762-620x/8000-000x: from 0.0.0, before 04.07.01 (FW29) (fixed in 04.07.01 (FW29)); from 0.0.0, before 04.07.01 (70) (fixed in 04.07.01 (70))
- Wago TP600 0762-630x/8000-000x: from 0.0.0, before 04.07.01 (FW29) (fixed in 04.07.01 (FW29)); from 0.0.0, before 04.07.01 (70) (fixed in 04.07.01 (70))
- Wago Wago CC100 0751-9x01: from 0.0.0, before 04.07.01 (FW29) (fixed in 04.07.01 (FW29))
Published 2025-06-16. Last modified 2026-06-17.