CVE-2026-4769: Wago 0765-110x/0100-0000

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessible without authentication for a brief period in the early boot phase. During this window, an unauthenticated remote attacker can gain access to the internal system processes, resulting in full system compromise.

Affected products

  • Wago 0765-110x/0100-0000: from 1.0.0.0, before 1.2.1.100 (fixed in 1.2.1.100)
  • Wago 0765-120x/0100-0000: from 1.0.0.0, before 1.2.7.100 (fixed in 1.2.7.100)
  • Wago 0765-150x/0100-0000: from 1.0.0.0, before 1.2.7.103 (fixed in 1.2.7.103)
  • Wago 0765-2101/0100-0000: from 1.0.0.0, before 1.2.1.102 (fixed in 1.2.1.102)
  • Wago 0765-2102/0100-0000: from 1.0.0.0, before 1.2.5.101 (fixed in 1.2.5.101)
  • Wago 0765-410x/0100-0000: from 1.0.0.0, before 1.2.1.100 (fixed in 1.2.1.100)
  • Wago 0765-420x/0100-0000: from 1.0.0.0, before 1.2.7.100 (fixed in 1.2.7.100)
  • Wago 0765-450x/0100-0000: from 1.0.0.0, before 1.2.7.103 (fixed in 1.2.7.103)

Published 2026-07-13. Last modified 2026-07-13.