CVE-2023-1698
published 2023-05-15CVE-2023-1698: In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can…
PriorityP192critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
82.04%
99.6th percentile
In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| wago | compact_controller_100_firmware | 20 – 23 | — |
| wago | compact_controller_cc100 | — | — |
| wago | compact_controller_cc100 | FW20 – FW22 | — |
| wago | edge_controller | — | — |
| wago | edge_controller_firmware | — | — |
| wago | pfc100 | — | — |
| wago | pfc100 | FW20 – FW22 | — |
| wago | pfc100_firmware | 20 – 23 | — |
| wago | pfc200 | — | — |
| wago | pfc200 | FW20 – FW22 | — |
| wago | pfc200_firmware | 20 – 23 | — |
| wago | touch_panel_600_advanced_firmware | — | — |
| wago | touch_panel_600_advanced_line | — | — |
| wago | touch_panel_600_marine_firmware | — | — |
| wago | touch_panel_600_marine_line | — | — |
| wago | touch_panel_600_standard_firmware | — | — |
| wago | touch_panel_600_standard_line | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect exploitation attempts by matching HTTP POST requests to the vulnerable licenses.php endpoint with a body containing shell metacharacters in the 'package' parameter (e.g., semicolons used for command injection). ↗
- →Successful exploitation responses will contain all four strings in the body: '"license":', '"name":', 'uid=', and 'gid=' — indicating OS command output (id command) embedded in the JSON response. ↗
- →Identify WAGO devices exposed on the internet using Shodan by searching for HTML content containing '/wbm/' and 'wago'. ↗
- →Identify WAGO devices exposed on the internet using FOFA by searching for body content containing '/wbm/' and 'wago'. ↗
- →The vulnerability is unauthenticated — no session cookie or Authorization header is required in the exploit request. Monitor for POST requests to /wbm/ paths from unauthenticated sources. ↗
- ·The path segment 'pfcXXX' in the vulnerable URL is a placeholder representing multiple WAGO PFC device variants; actual exploitation paths may vary by specific device model (e.g., pfc100, pfc200). ↗
- ·The CVE affects multiple WAGO products; the CPE listed covers Compact Controller 100 firmware but the vulnerability scope is broader across WAGO product lines. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vf3g-hqqf-r379: In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which
ghsa_unreviewed·2023-05-15
CVE-2023-1698 [CRITICAL] CWE-78 GHSA-vf3g-hqqf-r379: In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which
In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.
VulnCheck
wago compact_controller_100_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
vulncheck·2023·CVSS 9.8
CVE-2023-1698 [CRITICAL] wago compact_controller_100_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
wago compact_controller_100_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.
Affected: wago compact_controller_100_firmware
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2023-12-04&host_type=src&vulnerability=cve-2023-1698; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?da
No detection rules found.
Nuclei
WAGO - Remote Command Execution
nuclei·CVSS 9.8
CVE-2023-1698 [CRITICAL] WAGO - Remote Command Execution
WAGO - Remote Command Execution
In multiple products of WAGO, a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behavior, Denial of Service, and full system compromise.
Template:
id: CVE-2023-1698
info:
name: WAGO - Remote Command Execution
author: xianke
severity: critical
description: |
In multiple products of WAGO, a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behavior, Denial of Service, and full system compromise.
impact: |
Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the target system.
remediation: |
Apply the la
2023-05-15
Published
Exploited in the wild