Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsSeveral vulnerabilities in the web-based management (WBM) interface of specified WAGO controllers and Touch Panel 600 products could let unauthenticated attackers read or change device data. One flaw could allow root-privileged writes and potentially remote code execution. These are potential consequences—not evidence that an attack or industrial outage occurred.
What the WAGO vulnerabilities affect
The issue is in WAGO’s web-based management system, used for administration, commissioning and updates. CERT@VDE published advisory VDE-2022-060 on February 27, 2023, describing four flaws in the WBM of specified products. The advisory does not establish that every device in a product family is vulnerable; the exact model and firmware version matter. See the CERT@VDE advisory.
Four CVEs, with different consequences
- CVE-2022-45140 (CVSS 3.1: 9.8): An unauthenticated user could write arbitrary data to storage with root privileges. The advisory says this could enable remote code execution and full system compromise.
- CVE-2022-45138 (CVSS 3.1: 9.8): The configuration backend could be used without authentication to read or set device parameters, potentially leading to full device compromise. NVD also records CERT VDE’s Critical 9.8 assessment on its CVE-2022-45138 page.
- CVE-2022-45137 (CVSS 3.1: 6.1): Reflected cross-site scripting (XSS) could target a user’s browser. The advisory describes limited confidentiality and integrity impact, with no availability impact for this CVE.
- CVE-2022-45139 (CVSS 3.1: 5.3): A cross-origin resource sharing (CORS) misconfiguration could allow a malicious third-party web server to misuse basic information pages. Combined with CVE-2022-45138, it could disclose a limited amount of device information, such as CPU diagnostics.
CVSS scores rate vulnerability severity; they do not show that a flaw was exploited or how many installations are affected. The official sources cited here do not provide a count of attacks, compromised devices or outages.
Which WAGO products and firmware are listed as affected?
CERT@VDE lists the following products and firmware ranges. Match the complete model number and installed firmware to the advisory rather than assuming that every device with the same family name is affected.
#1 Best Overall
- 0 TO +55 DEGREES C
- 24 VDC
- 750 SERIES
- DIN RAIL MOUNT
- IP20
| Model or family | Product | Affected firmware listed by CERT@VDE |
|---|---|---|
| 751-9301 | Compact Controller 100 | FW16 through FW22; FW23 |
| 752-8303/8000-002 | Edge Controller | FW18 through FW22; FW23 |
| 750-81xx/xxx-xxx | PFC100 | FW16 through FW22; FW23 |
| 750-82xx/xxx-xxx | PFC200 | FW16 through FW22; FW23 |
| 762-5xxx | Touch Panel 600 Advanced Line | FW16 through FW22; FW23 |
| 762-6xxx | Touch Panel 600 Marine Line | FW16 through FW22; FW23 |
| 762-4xxx | Touch Panel 600 Standard Line | FW16 through FW22; FW23 |
NVD’s affected-configuration history for CVE-2022-45138 also lists these product lines. It records FW22 Patch 1 as unaffected and lists the FW23 configuration as affected. Because records and product guidance can change, use the vendor advisory and device-specific firmware status to determine applicability and the appropriate update. NVD’s CVE record reflects later updates to its configuration history, including changes in 2026.
Can the WAGO controller flaws be exploited remotely?
The advisory describes unauthenticated access to the configuration backend and a root-privileged write flaw. That means a login is not required for those specific attack paths; it does not mean every product or firmware version is exposed, or that the device is reachable from the public internet. Network reachability and whether an affected device is present are important to the risk.
Rank #2
- 10 AMP
- 10 VDC
- 125 MA
- 28-14 AWG
- -40 TO +85 DEGREES C
If an attacker could reach a vulnerable device, the highest-severity flaws could expose settings, alter data or potentially compromise the system. In an industrial environment, a compromised controller could create operational and safety risks, including process disruption. The advisory documents vulnerability potential, not a confirmed incident or outage.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to protect an affected WAGO PLC or panel
- Identify the exact device and firmware. Check the model number and installed firmware for each WAGO controller or Touch Panel 600 against the affected list in VDE-2022-060. Do not rely on the family name alone.
- Restrict network access. Limit connections to affected devices to the systems and administrators that need them. WAGO’s advisory says not to connect affected products directly to the internet.
- Disable WBM if it is not needed. CERT@VDE recommends deactivating the web-based management interface via the command line when it is unnecessary. Use the procedure appropriate to the device and its operating environment.
- Plan and install the recommended firmware. The advisory recommends FW22 Patch 1 or FW24 or higher for affected products. Confirm the correct device-specific update with WAGO before applying it; in a live industrial environment, account for change-control and operational requirements.
- Check for current vendor guidance. Confirm the device’s status and firmware recommendation with WAGO support or the current security notices before making changes.
WAGO’s Product Security Incident Response Team (PSIRT) says: “Whenever new potential threats arise, we provide recommendations, patches and updates as quickly as possible to minimize risks.” WAGO’s PSIRT page provides security-report guidance and points users to CERT@VDE for current WAGO security advisories. It also recommends contacting WAGO support if you are unsure whether a vulnerability applies to a product.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Quick Recap
Rank #4
- WAGO
- PLC-750-840
- Main controller
Rank #3
- 8-CHANNEL
- ADJUSTABLE
- ANALOG INPUT
- LIGHT GRAY
- RESISTANCE MEASUREMENT
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

