PT-2026-7084 · Wago · Wago 0852-1322
Diconium
·
Publicado
2026-02-09
·
Atualizado
2026-03-22
·
CVE-2026-22906
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
WAGO 0852-1322 (affected versions not specified)
Description
User credentials are stored using AES-ECB encryption with a hardcoded key. An unauthenticated remote attacker obtaining the configuration file can decrypt and recover plaintext usernames and passwords. This is especially concerning when combined with an authentication bypass. The issue poses a critical cybersecurity risk, particularly for organizations in the European Union's industrial sector.
Recommendations
Restrict access to the configuration file.
Monitor for unauthorized access attempts.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wago 0852-1322