CVE-2026-3587: Wago Industrial Managed Switch 852-1305
Critical severity, CVSS 10.0. EPSS: 0.7% chance of exploitation in the next 30 days.
An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, leading to full compromise of the device.
Affected products
- Wago Industrial Managed Switch 852-1305: from 0.0.0, before V1.2.0.S0 (fixed in V1.2.0.S0)
- Wago Industrial Managed Switch 852-1305-000-001: from 0.0.0, before V1.2.0.S0 (fixed in V1.2.0.S0)
- Wago Industrial Managed Switch 852-1505: from 0.0.0, before V1.1.9.S0 (fixed in V1.1.9.S0)
- Wago Industrial Managed Switch 852-1505-000-001: from 0.0.0, before V1.2.0.S0 (fixed in V1.2.0.S0)
- Wago Industrial Managed Switch 852-1605: from 0.0.0, before V1.2.5.S0 (fixed in V1.2.5.S0)
- Wago Industrial Managed Switch 852-303: from 0.0.0, before V1.2.8.S0 (fixed in V1.2.8.S0)
- Wago Industrial Managed Switch 852-602: from 0.0.0, before V1.0.6.S0 (fixed in V1.0.6.S0)
- Wago Industrial Managed Switch 852-603: from 0.0.0, before V1.0.6.S0 (fixed in V1.0.6.S0)
- Wago Lean Managed Switch 852-1812: from 0.0.0, before V1.2.1.S0 (fixed in V1.2.1.S0)
- Wago Lean Managed Switch 852-1812-010-000: from 0.0.0, before V1.2.1.S0 (fixed in V1.2.1.S0)
- Wago Lean Managed Switch 852-1813: from 0.0.0, before V1.2.1.S0 (fixed in V1.2.1.S0)
- Wago Lean Managed Switch 852-1813-000-001: from 0.0.0, before V1.2.3.S0 (fixed in V1.2.3.S0)
- Wago Lean Managed Switch 852-1813-010-000: from 0.0.0, before V1.2.1.S0 (fixed in V1.2.1.S0)
- Wago Lean Managed Switch 852-1813/010-001: from 0.0.0, before V1.2.1.S0 (fixed in V1.2.1.S0)
- Wago Lean Managed Switch 852-1816: from 0.0.0, before V1.2.1.S0 (fixed in V1.2.1.S0)
- Wago Lean Managed Switch 852-1816-010-000: from 0.0.0, before V1.2.1.S0 (fixed in V1.2.1.S0)
Published 2026-03-23. Last modified 2026-06-17.