PT-2026-7084 · Wago · Wago 0852-1322

Diconium

·

Published

2026-02-09

·

Updated

2026-03-22

·

CVE-2026-22906

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions WAGO 0852-1322 (affected versions not specified)
Description User credentials are stored using AES-ECB encryption with a hardcoded key. An unauthenticated remote attacker obtaining the configuration file can decrypt and recover plaintext usernames and passwords. This is especially concerning when combined with an authentication bypass. The issue poses a critical cybersecurity risk, particularly for organizations in the European Union's industrial sector.
Recommendations Restrict access to the configuration file. Monitor for unauthorized access attempts. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2026-01721
CVE-2026-22906

Affected Products

Wago 0852-1322