CVE-2025-41732
8.8WAGO · Industrial-Managed-Switches
An unauthenticated remote attacker can exploit a stack-based buffer overflow in the check_cookie function, potentially leading to full device compromise.
Executive summary
A critical stack-based buffer overflow vulnerability in WAGO Industrial-Managed-Switches allows an unauthenticated remote attacker to gain full control of the device.
Vulnerability
This vulnerability involves a stack-based buffer overflow (CWE-121) caused by unsafe sscanf calls within the check_cookie function, allowing an unauthenticated remote attacker to perform arbitrary memory writes.
Business impact
The exploitation of this vulnerability leads to full device compromise, which poses a severe risk to industrial control environments. Given the CVSS score of 8.8, successful attacks could result in complete loss of confidentiality, integrity, and availability, potentially leading to unauthorized network access, operational downtime, or the manipulation of industrial processes.
Remediation
Immediate Action: Update WAGO Industrial-Managed-Switches to version 02.64 or later to address the vulnerable function.
Proactive Monitoring: Inspect network traffic for malformed HTTP requests directed at management interfaces and monitor system logs for signs of unexpected crashes or service restarts.
Compensating Controls: Deploy a Web Application Firewall or network-level access control list to restrict access to the device management interface to trusted administrative IP addresses only.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability represents a significant security risk to industrial network infrastructure. Organizations utilizing affected WAGO switches should prioritize upgrading to the latest firmware version immediately, as the potential for full device compromise could facilitate further lateral movement within the operational technology network.
More WAGO CVEs
Sources
Originally found and disclosed by Daniel Hulliger from The Cyber-Defence Campus of armasuisse S+T, per the CVE Program record.