Vulnerabilities · 173 days ago

WAGO Switches Vulnerability Allows Full Device Compromise

WAGO industrial managed switches contain a hidden CLI function that an unauthenticated remote attacker can exploit to escape a restricted interface and fully compromise devices (CVE-2026-3587).

CVE-2026-3587

NVD KEV

CVSS 10 CRITICAL: an unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted… EPSS 0.7% (47th percentile).

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-03-27

Editions

Related stories