Vulnerability record · CVE-2023-1698 · published 15 May 2023
CVE-2023-1698: WAGO Controllers OS Command Injection Allows Unauthenticated User Creation
Wago · Compact Controller 100 Firmware
Multiple WAGO controller and touch panel firmware products contain an OS command injection flaw (CWE-78) that lets an unauthenticated, remote attacker create new users and alter device configuration. Because the affected devices are industrial controllers, successful exploitation can cause unintended behavior, denial of service, and full system compromise.
Description
In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, and full system compromise of industrial control devices, combined with a very high EPSS score, makes this an urgent patching priority.
What it is
Multiple WAGO controller and touch panel firmware products contain an OS command injection flaw (CWE-78) that lets an unauthenticated, remote attacker create new users and alter device configuration. Because the affected devices are industrial controllers, successful exploitation can cause unintended behavior, denial of service, and full system compromise.
Impact
An attacker gains the ability to create accounts and modify device configuration without credentials, leading to full control of the device and potential disruption of the controlled process. The CVSS vector indicates high confidentiality, integrity, and availability impact.
Attack surface
Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any network-exposed management or web interface on the listed WAGO products is the likely entry point.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high at 0.82037 (99.6th percentile), indicating substantial predicted exploitation activity. The only references are third-party advisories from CERT VDE, with no public exploit tags provided.
What to do
- Apply the firmware updates referenced in CERT VDE advisory VDE-2023-007 for all affected WAGO products.
- Remove affected controllers and touch panels from direct internet exposure; place them behind a firewall or VPN with strict access control.
- Restrict network access to device management interfaces to trusted engineering hosts and segments only.
- Audit device user accounts for unauthorized additions and review configuration for unexpected changes.
- Monitor vendor advisories for updated fixed firmware versions if the initial patch does not cover all listed products.
Detection
- Monitor device and network logs for new account creation or configuration changes on WAGO controllers outside approved maintenance windows.
- Alert on unexpected inbound connections to WAGO management or web interfaces from untrusted networks.
- Baseline and diff device configuration and user lists regularly to detect unauthorized modifications.
- Watch for command injection patterns or anomalous process execution on the controller if host-level telemetry is available.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://cert.vde.com/en/advisories/VDE-2023-007/ | Third Party Advisory |
| https://cert.vde.com/en/advisories/VDE-2023-007/ | Third Party Advisory |
Track CVE-2023-1698 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-1698), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.