← All Advisories

WAGO System I/O Field Series Activates an Undocumented Diagnostic Interface Without Authentication During Early Boot, Granting Unauthenticated Network Access for a Brief Window at Each Power Cycle

Last refreshed2026-09-28

Status: NEW  |  Advisory ID: CVE-2026-4769

Key Details

CVECVE-2026-4769
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-07-13
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Classified asCWE-912 (Hidden Functionality)

What to Know

Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessible without authentication for a brief period in the early boot phase. During this window, an unauthenticated remote attacker can gain access to the internal system processes, resulting in full system compromise. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-4769
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-4769