Junglewise Threat Intelligence

CVE-2025-41730: An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_account() function to write arbitrary data into fixed-size

CVE-2025-41730 · Severity: critical · CVSS 9.8 · Published 2025-12-10

Executive brief

An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_account() function to write arbitrary data into fixed-size stack buffers which leads to full device compromise.

Affected products

  • wago 0852-1322
  • wago 0852-1328_firmware
  • wago 0852-1328
  • wago 0852-1322_firmware

Related threats