CVE-2025-41730
8.8WAGO · Industrial-Managed-Switches
An unauthenticated remote attacker can exploit a stack-based buffer overflow in the check_account function of WAGO Industrial-Managed-Switches to achieve full device compromise.
Executive summary
A critical stack-based buffer overflow vulnerability in WAGO Industrial-Managed-Switches allows unauthenticated remote attackers to achieve full system compromise.
Vulnerability
The vulnerability is a stack-based buffer overflow (CWE-121) caused by unsafe sscanf calls within the check_account function. This flaw allows an unauthenticated remote attacker to perform arbitrary writes to fixed-size stack buffers.
Business impact
The potential for full device compromise poses a severe risk to operational technology environments where these switches are deployed. A successful exploit could lead to complete loss of network control, unauthorized data interception, or the disruption of critical industrial processes, justifying the high CVSS score of 8.8.
Remediation
Immediate Action: Organizations should review the official VDE advisory (VDE-2025-095) and apply the latest firmware updates provided by WAGO to address this vulnerability.
Proactive Monitoring: Monitor network traffic for unusual patterns targeting management interfaces and review system logs for signs of unauthorized authentication attempts or service crashes.
Compensating Controls: Implement strict network segmentation and utilize firewalls to restrict access to the device management interface to trusted administrative IP addresses only.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for full device compromise, this vulnerability represents a significant threat to industrial infrastructure. Administrators must prioritize the identification of affected WAGO switches and verify the availability of patches via the vendor advisory to mitigate the risk of remote exploitation.
More WAGO CVEs
Sources
Originally found and disclosed by Daniel Hulliger from The Cyber-Defence Campus of armasuisse S+T, per the CVE Program record.