cbcvebase.
CVE-2019-10712
published 2019-05-07

CVE-2019-10712: The Web-GUI on WAGO Series 750-88x (750-330, 750-352, 750-829, 750-831, 750-852, 750-880, 750-881, 750-882, 750-884, 750-885, 750-889) and Series 750-87x…

PriorityP260critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.76%
84.6th percentile
The Web-GUI on WAGO Series 750-88x (750-330, 750-352, 750-829, 750-831, 750-852, 750-880, 750-881, 750-882, 750-884, 750-885, 750-889) and Series 750-87x (750-830, 750-849, 750-871, 750-872, 750-873) devices has undocumented service access.

Affected

16 ranges
VendorProductVersion rangeFixed in
wago750-330_firmware< 1414
wago750-352_firmware< 1414
wago750-829_firmware< 1414
wago750-830_firmware< 0606
wago750-831_firmware< 1414
wago750-849_firmware< 0808
wago750-852_firmware< 1414
wago750-871_firmware< 1111
wago750-872_firmware< 0707
wago750-873_firmware< 0707
wago750-880_firmware< 1414
wago750-881_firmware< 1414
wago750-882_firmware< 1414
wago750-884_firmware< 1414
wago750-885_firmware< 1414
wago750-889_firmware< 1414

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability involves undocumented hard-coded credentials on the WAGO Web-GUI that allow unauthenticated remote access with administrator privileges; monitor for unexpected authenticated sessions to the web-based management interface on affected WAGO 750-88x and 750-87x devices, especially from unknown sources.
  • Monitor for unexpected FTP connections to affected WAGO PLC devices, as the hard-coded credentials can also be used for FTP access to exchange or delete the application.
  • Alert on changes to network port states (open/closed) on affected WAGO devices, as exploitation can be used to open closed network ports.
  • ·No known public exploits specifically target this vulnerability at time of advisory publication.
  • ·Affected firmware versions are Series 750-88x prior to FW14 and Series 750-87x at various firmware versions (FW06–FW11 depending on model); patched devices running current firmware are not affected.
  • ·The hard-coded credentials are undocumented; the exact credential values are not publicly disclosed in available sources, limiting signature-based detection of the specific credential string.

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.