Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-4769— Unauthenticated Access to Internal Diagnostic Interface

Quick assessment

Affected
WAGO 0765-110x/0100-0000
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WAGO 0765-150x/0100-0000是德国WAGO公司的一款自动化控制组件。 WAGO System I/O Field系列存在处理逻辑错误漏洞,该漏洞源于在初始启动序列期间激活的内部诊断功能未正式记录并在早期启动阶段短暂时间内无需身份验证即可访问,导致未经身份验证的远程攻击者可在此期间访问内部系统进程,造成系统完全被破解。以下版本受到影响:0765-110x/0100-0000 1.2.1.100之前版本、0765-120x/0100-0000 1.2.7.100之前版本、0765-150x

CVSS 9.8 · Critical EPSS 0.76% · P53

Affected Version Matrix 8

VendorProduct Version RangeStatus
WAGO 0765-110x/0100-0000 1.0.0.0< 1.2.1.100 affected
WAGO 0765-120x/0100-0000 1.0.0.0< 1.2.7.100 affected
WAGO 0765-150x/0100-0000 1.0.0.0< 1.2.7.103 affected
WAGO 0765-2101/0100-0000 1.0.0.0< 1.2.1.102 affected
WAGO 0765-2102/0100-0000 1.0.0.0< 1.2.5.101 affected
WAGO 0765-410x/0100-0000 1.0.0.0< 1.2.1.100 affected
WAGO 0765-420x/0100-0000 1.0.0.0< 1.2.7.100 affected
WAGO 0765-450x/0100-0000 1.0.0.0< 1.2.7.103 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-4769

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Unauthenticated Access to Internal Diagnostic Interface
Source: CVE Program / CVE List V5
Vulnerability Description
Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessible without authentication for a brief period in the early boot phase. During this window, an unauthenticated remote attacker can gain access to the internal system processes, resulting in full system compromise.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
隐藏功能
Source: CVE Program / CVE List V5
Vulnerability Title
WAGO 0765-150x/0100-0000 处理逻辑错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
WAGO 0765-150x/0100-0000是德国WAGO公司的一款自动化控制组件。 WAGO System I/O Field系列存在处理逻辑错误漏洞,该漏洞源于在初始启动序列期间激活的内部诊断功能未正式记录并在早期启动阶段短暂时间内无需身份验证即可访问,导致未经身份验证的远程攻击者可在此期间访问内部系统进程,造成系统完全被破解。以下版本受到影响:0765-110x/0100-0000 1.2.1.100之前版本、0765-120x/0100-0000 1.2.7.100之前版本、0765-150x
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
WAGO 0765-110x/0100-0000 1.0.0.0 ~ 1.2.1.100 -
WAGO 0765-120x/0100-0000 1.0.0.0 ~ 1.2.7.100 -
WAGO 0765-150x/0100-0000 1.0.0.0 ~ 1.2.7.103 -
WAGO 0765-2101/0100-0000 1.0.0.0 ~ 1.2.1.102 -
WAGO 0765-2102/0100-0000 1.0.0.0 ~ 1.2.5.101 -
WAGO 0765-410x/0100-0000 1.0.0.0 ~ 1.2.1.100 -
WAGO 0765-420x/0100-0000 1.0.0.0 ~ 1.2.7.100 -
WAGO 0765-450x/0100-0000 1.0.0.0 ~ 1.2.7.103 -

II. Public POCs for CVE-2026-4769

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-4769

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-4769 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-4769

No comments yet


Leave a comment