CVE-2026-3587
CVSS 10 CRITICAL: an unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted… EPSS 0.7% (47th percentile).
Vulnerabilities & Exploits · IoT / OT Attack
WAGO industrial managed switches contain a hidden CLI function that an unauthenticated remote attacker can exploit to escape a restricted interface and fully compromise devices (CVE-2026-3587).
1 source · Mar 26
CVSS 10 CRITICAL: an unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted… EPSS 0.7% (47th percentile).
CISA Advisories
WAGO GmbH & Co. KG Industrial Managed Switches | CISA
KG Industrial Managed Switches Summary An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, leading to full compromise of the device.
originalPart of the PlainSec briefing for 2026-03-27
Every edition of this story: WAGO Switches Vulnerability Allows Full Device Compromise