cbcvebase.
CVE-2024-1490
published 2026-04-09

CVE-2024-1490: An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management interface of a WAGO PLC. If…

PriorityP352high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.73%
49.9th percentile
An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management interface of a WAGO PLC. If user-defined scripts are permitted, OpenVPN may allow the execution of arbitrary shell commands enabling the attacker to run arbitrary commands on the device.

Affected

9 ranges
VendorProductVersion rangeFixed in
wagocc1000.0.0 – 4.5.10
wagoedge_controller0.0.0 – 4.5.10
wagopfc100_g10.0.0 – 3.10.10
wagopfc100_g20.0.0 – 4.5.10
wagopfc200_g10.0.0 – 3.10.10
wagopfc200_g20.0.0 – 4.5.10
wagotp600
wagotp6000.0.0 – FW 26
wagowp4000.0.0 – 4.5.10
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.