Wago Pfc200 G2 750-821X-Xxx-Xxx vulnerabilities

12 known vulnerabilities affecting wago/pfc200_g2_750-821x-xxx-xxx.

Total CVEs
12
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM7

Vulnerabilities

Page 1 of 1
CVE-2025-25265MEDIUMCVSS 4.9≥ 0.0.0, < 04.07.01 (FW29)≥ 0.0.0, < 04.07.01 (70)2025-06-16
CVE-2025-25265 [MEDIUM] CWE-306 CVE-2025-25265: A web application for configuring the controller is accessible at a specific path. It contains an en A web application for configuring the controller is accessible at a specific path. It contains an endpoint that allows a high privileged remote attacker to read files from the system’s file structure.
cvelistv5nvd
CVE-2025-25264MEDIUMCVSS 6.5≥ 0.0.0, < 04.07.01 (FW29)≥ 0.0.0, < 04.07.01 (70)2025-06-16
CVE-2025-25264 [MEDIUM] CWE-942 CVE-2025-25264: An unauthenticated remote attacker can trick an admin to visit a website containing malicious java s An unauthenticated remote attacker can trick an admin to visit a website containing malicious java script code. The current overly permissive CORS policy allows the attacker to obtain any files from the file system.
cvelistv5nvd
CVE-2025-0101MEDIUMCVSS 6.5fixed in 04.07.012025-04-16
CVE-2025-0101 [MEDIUM] CWE-190 CVE-2025-0101: A low privileged user can set the date of the devices to the 19th of January 2038 an therefore excee A low privileged user can set the date of the devices to the 19th of January 2038 an therefore exceed the 32-Bit time limit. This causes some functions to work unexpected or stop working at all. Both during runtime and after a restart.
cvelistv5nvd
CVE-2024-12650MEDIUMCVSS 5.4fixed in 04.07.012025-03-05
CVE-2024-12650 [MEDIUM] CWE-252 CVE-2024-12650: An attacker with low privileges can manipulate the requested memory size, causing the application to An attacker with low privileges can manipulate the requested memory size, causing the application to use an invalid memory area. This could lead to a crash of the application but it does not affected other applications.
cvelistv5nvd
CVE-2024-41974HIGHCVSS 7.1≥ 0.0.0, ≤ 4.5.10 (FW27)2024-11-18
CVE-2024-41974 [HIGH] CWE-732 CVE-2024-41974: A low privileged remote attacker may modify the BACNet service properties due to incorrect permissio A low privileged remote attacker may modify the BACNet service properties due to incorrect permission assignment for critical resources which may lead to a DoS limited to BACNet communication.
cvelistv5nvd
CVE-2024-41967HIGHCVSS 8.1≥ 0.0.0, ≤ 4.5.10 (FW27)2024-11-18
CVE-2024-41967 [HIGH] CWE-306 CVE-2024-41967: A low privileged remote attacker may modify the boot mode configuration setup of the device, leading A low privileged remote attacker may modify the boot mode configuration setup of the device, leading to modification of the firmware upgrade process or a denial-of-service attack.
cvelistv5nvd
CVE-2024-41971HIGHCVSS 8.1≥ 0.0.0, ≤ 4.5.10 (FW27)2024-11-18
CVE-2024-41971 [HIGH] CWE-22 CVE-2024-41971: A low privileged remote attacker can overwrite an arbitrary file on the filesystem leading to a DoS A low privileged remote attacker can overwrite an arbitrary file on the filesystem leading to a DoS and data loss.
cvelistv5nvd
CVE-2024-41969HIGHCVSS 8.8≥ 0.0.0, ≤ 4.5.10 (FW27)2024-11-18
CVE-2024-41969 [HIGH] CWE-306 CVE-2024-41969: A low privileged remote attacker may modify the configuration of the CODESYS V3 service through a mi A low privileged remote attacker may modify the configuration of the CODESYS V3 service through a missing authentication vulnerability which could lead to full system access and/or DoS.
cvelistv5nvd
CVE-2024-41973HIGHCVSS 8.1≥ 0.0.0, ≤ 4.5.10 (FW27)2024-11-18
CVE-2024-41973 [HIGH] CWE-35 CVE-2024-41973: A low privileged remote attacker can specify an arbitrary file on the filesystem which may lead to a A low privileged remote attacker can specify an arbitrary file on the filesystem which may lead to an arbitrary file writes with root privileges.
cvelistv5nvd
CVE-2024-41970MEDIUMCVSS 5.7≥ 0.0.0, ≤ 4.5.10 (FW27)2024-11-18
CVE-2024-41970 [MEDIUM] CWE-732 CVE-2024-41970: A low privileged remote attacker may gain access to forbidden diagnostic data due to incorrect permi A low privileged remote attacker may gain access to forbidden diagnostic data due to incorrect permission assignment for critical resources.
cvelistv5nvd
CVE-2024-41972MEDIUMCVSS 6.5≥ 0.0.0, ≤ 4.5.10 (FW27)2024-11-18
CVE-2024-41972 [MEDIUM] CWE-35 CVE-2024-41972: A low privileged remote attacker can overwrite an arbitrary file on the filesystem which may lead to A low privileged remote attacker can overwrite an arbitrary file on the filesystem which may lead to an arbitrary file read with root privileges.
cvelistv5nvd
CVE-2024-41968MEDIUMCVSS 5.4≥ 0.0.0, ≤ 4.5.10 (FW27)2024-11-18
CVE-2024-41968 [MEDIUM] CWE-306 CVE-2024-41968: A low privileged remote attacker may modify the docker settings setup of the device, leading to a li A low privileged remote attacker may modify the docker settings setup of the device, leading to a limited DoS.
cvelistv5nvd