peter bassill · operator
$ cve CVE-2018-12979 JSON

CVE-2018-12979 EXPLOIT

6.5
MEDIUM · CVSS 3.1 · EPSS 7.8% (pctl 94)

Patch early

A public exploit exists.

Description

An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. Weak permissions allow an authenticated user to overwrite critical files by abusing the unrestricted file upload in the WBM.

Scoring

CVSS6.5 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS7.78% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-732
On CISA KEVno
Public exploityes
Published2018-07-12
Last modified2026-06-17

Affected (8)

VendorProduct
wago762-3000
wago762-3000 firmware
wago762-3001
wago762-3001 firmware
wago762-3002
wago762-3002 firmware
wago762-3003
wago762-3003 firmware

Public exploits

SourceTitleDate
exploit-dbWAGO e!DISPLAY 7300T - Multiple Vulnerabilities2018-07-13

References

→ the Explorer  ·  watch your stack  ·  NVD