Junglewise Threat Intelligence

CVE-2026-4769: WAGO System I/O Field undocumented diagnostic exposure in boot phase

CVE-2026-4769 · Severity: critical · CVSS 9.8 · Published 2026-07-13

Executive brief

WAGO System I/O Field devices, which are used in industrial automation to connect sensors and actuators to control systems, contain an undocumented diagnostic feature that activates during startup. An attacker with network access could exploit this brief window during the boot process to bypass security controls and take full control of the device. This could lead to unauthorized changes in industrial processes, data theft, or complete service disruption.

Technical details

The vulnerability is classified as Hidden Functionality (CWE-912) within the firmware of WAGO System I/O Field devices. During the early boot phase, the device exposes an undocumented diagnostic interface that does not require authentication. If an attacker has network reachability to the device during this specific startup window, they can interact with internal system processes before standard security mechanisms are initialized. This allows for an unauthenticated remote attacker to achieve full system compromise, including unauthorized configuration changes and execution of arbitrary commands. WAGO has released firmware updates to address this exposure across the affected product lines.

Affected products

  • WAGO 0765-110x/0100-0000 1.0.0.0 to < 1.2.1.100
  • WAGO 0765-120x/0100-0000 1.0.0.0 to < 1.2.7.100
  • WAGO 0765-150x/0100-0000 1.0.0.0 to < 1.2.7.103
  • WAGO 0765-2101/0100-0000 1.0.0.0 to < 1.2.1.102
  • WAGO 0765-2102/0100-0000 1.0.0.0 to < 1.2.5.101
  • WAGO 0765-410x/0100-0000 1.0.0.0 to < 1.2.1.100
  • WAGO 0765-420x/0100-0000 1.0.0.0 to < 1.2.7.100
  • WAGO 0765-450x/0100-0000 1.0.0.0 to < 1.2.7.103

Timeline

  • 2026-07-13: advisory: Initial advisory published by CERT VDE and WAGO
  • 2026-07-13: patched: Fixed firmware versions released for all affected models

References