🔐 CVE Alert

CVE-2024-1490

HIGH 7.2

Wago: Vulnerability in WBM through Open VPN

CVSS Score
7.2
EPSS Score
0.2%
EPSS Percentile
46th

An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management interface of a WAGO PLC. If user-defined scripts are permitted, OpenVPN may allow the execution of arbitrary shell commands enabling the attacker to run arbitrary commands on the device.

CWE CWE-94
Vendor wago
Product cc100 (0751-9x01)
Published Apr 9, 2026
Last Updated Apr 9, 2026
Stay Ahead of the Next One

Get instant alerts for wago cc100 (0751-9x01)

Be the first to know when new high vulnerabilities affecting wago cc100 (0751-9x01) are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

WAGO / CC100 (0751-9x01)
0.0.0 ≤ 4.5.10
WAGO / PFC100 G1 (0750-810-xxxx-xxxx)
0.0.0 ≤ 3.10.10
WAGO / PFC100 G2 (0750-811x-xxxx-xxxx)
0.0.0 ≤ 4.5.10
WAGO / PFC200 G1 (750-820x-xxxx-xxxx)
0.0.0 ≤ 3.10.10
WAGO / PFC200 G2 (750-821x-xxxx-xxxx)
0.0.0 ≤ 4.5.10
WAGO / TP600 (0762-420x-8000-000x)
0.0.0 ≤ FW 26
WAGO / TP600 (0762-430x-8000-000x)
0.0.0 ≤ 4.5.10
WAGO / TP600 (0762-520x-8000-000x)
0.0.0 ≤ 4.5.10
WAGO / TP600 (0762-530x-8000-000x)
0.0.0 ≤ 4.5.10
WAGO / TP600 (0762-620x-8000-000x)
0.0.0
WAGO / TP600 (0762-630x-8000-000x)
0.0.0 ≤ 4.5.10
WAGO / Edge Controller (0752-8303-8000-0002)
0.0.0 ≤ 4.5.10
WAGO / WP400 (0762-340x)
0.0.0 ≤ 4.5.10

References

NVD ↗ CVE.org ↗ EPSS Data ↗
certvde.com: https://certvde.com/de/advisories/VDE-2024-008 wago.csaf-tp.certvde.com: https://wago.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2024-008.json

Credits

🔍 Jeroen Wijenbergh, Floris Hendriks from Radboud University