PT-2026-7084 · Wago · Wago 0852-1322
Diconium
·
Published
2026-02-09
·
Updated
2026-03-22
·
CVE-2026-22906
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
WAGO 0852-1322 (affected versions not specified)
Description
User credentials are stored using AES-ECB encryption with a hardcoded key. An unauthenticated remote attacker obtaining the configuration file can decrypt and recover plaintext usernames and passwords. This is especially concerning when combined with an authentication bypass. The issue poses a critical cybersecurity risk, particularly for organizations in the European Union's industrial sector.
Recommendations
Restrict access to the configuration file.
Monitor for unauthorized access attempts.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wago 0852-1322