← Vulnerability feed

Vulnerability record · CVE-2023-1698 · published 15 May 2023

CVE-2023-1698: WAGO Controllers OS Command Injection Allows Unauthenticated User Creation

Wago · Compact Controller 100 Firmware

Multiple WAGO controller and touch panel firmware products contain an OS command injection flaw (CWE-78) that lets an unauthenticated, remote attacker create new users and alter device configuration. Because the affected devices are industrial controllers, successful exploitation can cause unintended behavior, denial of service, and full system compromise.

9.8 CVSS 3.1 Critical EPSS 82% · top 0.4% CWE-78 · OS command injection
9.8CVSS 3.1 base score
82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
7Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network reachability, no authentication, and full system compromise of industrial control devices, combined with a very high EPSS score, makes this an urgent patching priority.

What it is

Multiple WAGO controller and touch panel firmware products contain an OS command injection flaw (CWE-78) that lets an unauthenticated, remote attacker create new users and alter device configuration. Because the affected devices are industrial controllers, successful exploitation can cause unintended behavior, denial of service, and full system compromise.

Impact

An attacker gains the ability to create accounts and modify device configuration without credentials, leading to full control of the device and potential disruption of the controlled process. The CVSS vector indicates high confidentiality, integrity, and availability impact.

Attack surface

Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any network-exposed management or web interface on the listed WAGO products is the likely entry point.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high at 0.82037 (99.6th percentile), indicating substantial predicted exploitation activity. The only references are third-party advisories from CERT VDE, with no public exploit tags provided.

What to do

  • Apply the firmware updates referenced in CERT VDE advisory VDE-2023-007 for all affected WAGO products.
  • Remove affected controllers and touch panels from direct internet exposure; place them behind a firewall or VPN with strict access control.
  • Restrict network access to device management interfaces to trusted engineering hosts and segments only.
  • Audit device user accounts for unauthorized additions and review configuration for unexpected changes.
  • Monitor vendor advisories for updated fixed firmware versions if the initial patch does not cover all listed products.

Detection

  • Monitor device and network logs for new account creation or configuration changes on WAGO controllers outside approved maintenance windows.
  • Alert on unexpected inbound connections to WAGO management or web interfaces from untrusted networks.
  • Baseline and diff device configuration and user lists regularly to detect unauthorized modifications.
  • Watch for command injection patterns or anomalous process execution on the controller if host-level telemetry is available.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-1698 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-45138Wago 751-9301 firmware missing authentication for critical function vulnerabilityThe configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use t…EPSS 0.74%9.8CVE-2022-45140Wago 751-9301 firmware missing authentication for critical function vulnerabilityThe configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthentic…EPSS 1.1%9.8CVE-2020-12522Wago pfc 100 firmware os command injection vulnerabilityThe reported vulnerability allows an attacker who has network access to the device to execute code with specially crafted packets in WAGO Series PFC …EPSS 3.1%9.8CVE-2019-5082Wago pfc200 firmware out-of-bounds write vulnerabilityAn exploitable heap buffer overflow vulnerability exists in the iocheckd service I/O-Check functionality of WAGO PFC200 Firmware version 03.01.07(13)…EPSS 3.3%9.8CVE-2018-5459Wago pfc200 firmware improper authentication vulnerabilityAn Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An attacker can execute different …EPSS 2.7%9.1CVE-2019-5160Wago pfc200 firmware vulnerabilityAn exploitable improper host validation vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 Firmware versions 03.02.02(14), 0…EPSS 2.7%9.1CVE-2019-5161Wago pfc200 firmware insufficient verification of data authenticity vulnerabilityAn exploitable remote code execution vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 versions 03.02.02(14), 03.01.07(13),…EPSS 2.5%9.1CVE-2016-9362Wago pfc200 firmware improper authentication vulnerabilityAn issue was discovered in WAGO 750-8202/PFC200 prior to FW04 (released August 2015), WAGO 750-881 prior to FW09 (released August 2016), and WAGO 075…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2023-1698), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.