Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-4769: WAGO System I/O Field devices expose internal diagnostics during startup
CVE-2026-4769
Summary
WAGO System I/O Field devices have a hidden diagnostic mode that becomes accessible for a short time during startup. This allows an attacker to access the device's internal processes without a password, potentially giving them control over the device. To fix this issue, update to the latest firmware or follow WAGO's recommended security guidelines.
Original title
Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessi...
Original description
Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessible without authentication for a brief period in the early boot phase. During this window, an unauthenticated remote attacker can gain access to the internal system processes, resulting in full system compromise.
nvd CVSS3.1
9.8
nvd CVSS4.0
9.3
Vulnerability type
CWE-912
Published: 13 Jul 2026 · Updated: 20 Jul 2026 · First seen: 13 Jul 2026