CVE-2026-22904: Wago 0852-1322
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated remote attacker to send oversized cookie values and trigger a stack buffer overflow, resulting in a denial‑of‑service condition and possible remote code execution.
Affected products
- Wago 0852-1322: from 0.0.0, up to and including 2.64; version 2.64 only
- Wago 0852-1328: from 0.0.0, up to and including 2.64; version 2.64 only
Published 2026-02-09. Last modified 2026-06-17.