cbcvebase.
CVE-2022-45137
published 2023-02-27

CVE-2022-45137: The configuration backend of the web-based management is vulnerable to reflected XSS (Cross-Site Scripting) attacks that targets the users browser. This leads…

PriorityP424medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.38%
29.8th percentile
The configuration backend of the web-based management is vulnerable to reflected XSS (Cross-Site Scripting) attacks that targets the users browser. This leads to a limited impact of confidentiality and integrity but no impact of availability.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
wago751-9301_firmware
wago751-9301_firmware
wago751-9301_firmware>= 16 < 2222
wago752-8303_8000-002_firmware
wago752-8303_8000-002_firmware
wago752-8303_8000-002_firmware>= 18 < 2222
wagocompact_controller_cc100
wagocompact_controller_cc100>= FW16 < FW22FW22
wagoedge_controller
wagoedge_controller>= FW18 < FW22FW22
wagopfc100
wagopfc100>= FW16 < FW22FW22
wagopfc100_firmware
wagopfc100_firmware
wagopfc100_firmware>= 16 < 2222
wagopfc200
wagopfc200>= FW16 < FW22FW22
wagopfc200_firmware
wagopfc200_firmware
wagopfc200_firmware>= 16 < 2222
wagotouch_panel_600_advanced_firmware
wagotouch_panel_600_advanced_firmware
wagotouch_panel_600_advanced_firmware>= 16 < 2222
wagotouch_panel_600_advanced_line
wagotouch_panel_600_advanced_line>= FW16 < FW22FW22
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.