CVE-2025-41715: Wago Device Sphere
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
The database for the web application is exposed without authentication, allowing an unauthenticated remote attacker to gain unauthorized access and potentially compromise it.
Affected products
- Wago Device Sphere: from 0.0.0, before 1.1.0 (fixed in 1.1.0)
- Wago Solution Builder: from 0.0.0, before 2.3.3 (fixed in 2.3.3)
Published 2025-09-24. Last modified 2026-09-26.