cbcvebase.
CVE-2026-22905
published 2026-02-09

CVE-2026-22905: An unauthenticated remote attacker can bypass authentication by exploiting insufficient URI validation and using path traversal sequences (e.g.…

high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
An unauthenticated remote attacker can bypass authentication by exploiting insufficient URI validation and using path traversal sequences (e.g., /js/../cgi-bin/post.cgi), gaining unauthorized access to protected CGI endpoints and configuration downloads.

Affected

4 ranges
VendorProductVersion rangeFixed in
wago0852-1322
wago0852-13220.0.0 – 2.64
wago0852-1328
wago0852-13280.0.0 – 2.64