Vulnerabilità ed exploit · Attacco IoT / OT

Switch WAGO Consentono Compromissione Completa dei Dispositivi

Switch industriali managed di WAGO contengono una funzione CLI nascosta che un attaccante remoto non autenticato può sfruttare. Sfruttando la funzione l'attaccante può evadere l'interfaccia ristretta e compromettere completamente il dispositivo (CVE-2026-3587).

1 fonte · 26 mar

CVE-2026-3587

NVD KEV

CVSS 10 CRITICAL: an unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted… EPSS 0.7% (49º percentile).

Cronologia

Fonti

Part of the PlainSec briefing for 2026-03-27

Every edition of this story: Switch WAGO Consentono Compromissione Completa dei Dispositivi

Altro da oggi