peter bassill · operator
$ cve CVE-2019-12549 JSON

CVE-2019-12549

9.8
CRITICAL · CVSS 3.0 · EPSS 3.3% (pctl 88)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded private keys for the SSH daemon. The fingerprint of the SSH host key from the corresponding SSH daemon matches the embedded private key.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.26% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-798
On CISA KEVno
Public exploitnone known
Published2019-06-17
Last modified2026-06-17

Affected (6)

VendorProduct
wago852-1305
wago852-1305 firmware
wago852-1505
wago852-1505 firmware
wago852-303
wago852-303 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD