CVE-2025-41753: Wago 0750-811x-Xxxx-Xxxx
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise.
Affected products
- Wago 0750-811x-Xxxx-Xxxx: from 1.0.0, before 4.8.9 (fixed in 4.8.9); from 1.0.0, before 4.8.9 (70) (fixed in 4.8.9 (70))
- Wago 0750-821x-Xxx-Xxx: from 1.0.0, before 4.8.9 (fixed in 4.8.9); from 1.0.0, before 4.8.9 (70) (fixed in 4.8.9 (70))
- Wago 0751-9x01: from 1.0.0, before 4.8.9 (fixed in 4.8.9); from 1.0.0, before 4.8.9 (70) (fixed in 4.8.9 (70))
- Wago 0752-8303-8000-0002: from 1.0.0, before 4.8.9 (fixed in 4.8.9); from 1.0.0, before 4.8.9 (70) (fixed in 4.8.9 (70))
- Wago 0762-340x: from 1.0.0, before 4.8.9 (fixed in 4.8.9); from 1.0.0, before 4.8.9 (70) (fixed in 4.8.9 (70))
- Wago 0762-420x-8000-000x: from 1.0.0, before 4.8.9 (fixed in 4.8.9); from 1.0.0, before 4.8.9 (70) (fixed in 4.8.9 (70))
- Wago 0762-430x-8000-000x: from 1.0.0, before 4.8.9 (fixed in 4.8.9); from 1.0.0, before 4.8.9 (70) (fixed in 4.8.9 (70))
- Wago 0762-520x-8000-000x: from 1.0.0, before 4.8.9 (fixed in 4.8.9); from 1.0.0, before 4.8.9 (70) (fixed in 4.8.9 (70))
- Wago 0762-530x-8000-000x: from 1.0.0, before 4.8.9 (fixed in 4.8.9); from 1.0.0, before 4.8.9 (70) (fixed in 4.8.9 (70))
- Wago 0762-620x-8000-000x: from 1.0.0, before 4.8.9 (fixed in 4.8.9); from 1.0.0, before 4.8.9 (70) (fixed in 4.8.9 (70))
- Wago 0762-630x-8000-000x: from 1.0.0, before 4.8.9 (fixed in 4.8.9); from 1.0.0, before 4.8.9 (70) (fixed in 4.8.9 (70))
Published 2026-10-01. Last modified 2026-10-01.