CVE-2024-1490
Wago: Vulnerability in WBM through Open VPN
CVSS Score
7.2
EPSS Score
0.2%
EPSS Percentile
46th
An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management interface of a WAGO PLC. If user-defined scripts are permitted, OpenVPN may allow the execution of arbitrary shell commands enabling the attacker to run arbitrary commands on the device.
| CWE | CWE-94 |
| Vendor | wago |
| Product | cc100 (0751-9x01) |
| Published | Apr 9, 2026 |
| Last Updated | Apr 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for wago cc100 (0751-9x01)
Be the first to know when new high vulnerabilities affecting wago cc100 (0751-9x01) are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
WAGO / CC100 (0751-9x01)
0.0.0 ≤ 4.5.10
WAGO / PFC100 G1 (0750-810-xxxx-xxxx)
0.0.0 ≤ 3.10.10
WAGO / PFC100 G2 (0750-811x-xxxx-xxxx)
0.0.0 ≤ 4.5.10
WAGO / PFC200 G1 (750-820x-xxxx-xxxx)
0.0.0 ≤ 3.10.10
WAGO / PFC200 G2 (750-821x-xxxx-xxxx)
0.0.0 ≤ 4.5.10
WAGO / TP600 (0762-420x-8000-000x)
0.0.0 ≤ FW 26
WAGO / TP600 (0762-430x-8000-000x)
0.0.0 ≤ 4.5.10
WAGO / TP600 (0762-520x-8000-000x)
0.0.0 ≤ 4.5.10
WAGO / TP600 (0762-530x-8000-000x)
0.0.0 ≤ 4.5.10
WAGO / TP600 (0762-620x-8000-000x)
0.0.0
WAGO / TP600 (0762-630x-8000-000x)
0.0.0 ≤ 4.5.10
WAGO / Edge Controller (0752-8303-8000-0002)
0.0.0 ≤ 4.5.10
WAGO / WP400 (0762-340x)
0.0.0 ≤ 4.5.10
References
Credits
🔍 Jeroen Wijenbergh, Floris Hendriks from Radboud University