CVE-2026-22903: Wago 0852-1322

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

An unauthenticated remote attacker can send a crafted HTTP request containing an overly long SESSIONID cookie. This can trigger a stack buffer overflow in the modified lighttpd server, causing it to crash and potentially enabling remote code execution due to missing stack protections.

Affected products

  • Wago 0852-1322: from 0.0.0, up to and including 2.64; version 2.64 only
  • Wago 0852-1328: from 0.0.0, up to and including 2.64; version 2.64 only

Published 2026-02-09. Last modified 2026-06-17.