CVE-2024-1490
published 2026-04-09CVE-2024-1490: An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management interface of a WAGO PLC. If…
PriorityP352high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.73%
49.9th percentile
An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management interface of a WAGO PLC. If user-defined scripts are permitted, OpenVPN may allow the execution of arbitrary shell commands enabling the attacker to run arbitrary commands on the device.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| wago | cc100 | 0.0.0 – 4.5.10 | — |
| wago | edge_controller | 0.0.0 – 4.5.10 | — |
| wago | pfc100_g1 | 0.0.0 – 3.10.10 | — |
| wago | pfc100_g2 | 0.0.0 – 4.5.10 | — |
| wago | pfc200_g1 | 0.0.0 – 3.10.10 | — |
| wago | pfc200_g2 | 0.0.0 – 4.5.10 | — |
| wago | tp600 | — | — |
| wago | tp600 | 0.0.0 – FW 26 | — |
| wago | wp400 | 0.0.0 – 4.5.10 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-09
Published