CVE-2024-1490
Received
Received - Intake
Arbitrary Command Execution via OpenVPN in WAGO PLC
Publication date: 2026-04-09
Last updated on: 2026-04-09
Assigner: CERT VDE
Description
Description
An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management interface of a WAGO PLC. If user-defined scripts are permitted, OpenVPN may allow the execution of arbitrary shell commands enabling the attacker to run arbitrary commands on the device.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| wago | wago_os_linux | to 4.5.10 (inc) |
| wago | cc100 | * |
| wago | pfc100_g1 | * |
| wago | pfc100_g2 | * |
| wago | pfc200_g1 | * |
| wago | pfc200_g2 | * |
| wago | tp600 | * |
| wago | edge_controller | * |
| wago | wp400 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-94 | The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment. |