peter bassill · operator
$ cve CVE-2020-12522 JSON

CVE-2020-12522

10.0
CRITICAL · CVSS 3.1 · EPSS 3.1% (pctl 87)

In your normal cycle

Critical by CVSS (10), but no sign of active exploitation.

Description

The reported vulnerability allows an attacker who has network access to the device to execute code with specially crafted packets in WAGO Series PFC 100 (750-81xx/xxx-xxx), Series PFC 200 (750-82xx/xxx-xxx), Series Wago Touch Panel 600 Standard Line (762-4xxx), Series Wago Touch Panel 600 Advanced Line (762-5xxx), Series Wago Touch Panel 600 Marine Line (762-6xxx) with firmware versions <=FW10.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS3.05% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2020-12-17
Last modified2026-06-17

Affected (40)

VendorProduct
wago750-8101\/025-000
wago750-8102\/025-000
wago750-8202\/000-012
wago750-8202\/000-022
wago750-8202\/040-000
wago750-8202\/040-001
wago750-8206\/025-000
wago750-8206\/025-001
wago750-8206\/040-000
wago750-8206\/040-001
wago750-8207\/025-000
wago750-8207\/025-001
wago750-8208\/025-000
wago750-8208\/025-001
wago750-8210\/025-000
wago750-8210\/040-000
wago750-8211\/040-000
wago750-8211\/040-001
wago750-8212\/025-000
wago750-8212\/025-001
wago750-8212\/025-002
wago750-8212\/040-000
wago750-8212\/040-010
wago750-8213\/040-010
wago750-8216\/025-000
wago750-8216\/025-001
wago750-8217\/025-000
wago762-4301\/8000-002
wago762-4302\/8000-002
wago762-4303\/8000-002
wago762-4304\/8000-002
wago762-5303\/8000-002
wago762-5304\/8000-002
wago762-6201\/8000-001
wago762-6202\/8000-001
wagopfc 100 firmware
wagopfc 200 firmware
wagotouch panel 600 advanced firmware
wagotouch panel 600 marine firmware
wagotouch panel 600 standard firmware

References

→ the Explorer  ·  watch your stack  ·  NVD