External risk intelligence

Wago Stack Buffer Overflow Vulnerability Allows Full Device Compromise

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-41730

The vulnerability affects industrial networking equipment (switches). While such devices are primarily intended for internal or OT network management, they are sometimes misconfigured or intentionally exposed to the internet, making public reachability possible but not the standard or intended deployment pattern.

Out-of-bounds Write

Wago 0852 1328 Firmware

before 02.64

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability allows an unauthenticated remote attacker to gain full control of affected devices by exploiting unsafe programming practices. The issue lies in the way the device handles account checking, potentially enabling attackers to write arbitrary data into memory, leading to a complete compromise of the device's functionality.

  • Attackers can fully control devices remotely.
  • Critical vulnerability impacting industrial networking equipment.
  • Confirm relevance and exposure for potential impact.

Attack Path

How an attacker could exploit the issue

An attacker can remotely target this vulnerability without any authentication. By sending specially crafted data, they can exploit unsafe string parsing within a function that checks account information. This allows arbitrary data to be written to memory, potentially leading to complete control over the affected device.

  • No authentication required.
  • Exploits unsafe string parsing.
  • Leads to full device compromise.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated remote attacker to compromise the entire device by writing arbitrary data to memory. This is possible when the `check_account()` function is called and the unsafe `sscanf` function is used, leading to a buffer overflow.

  • Device compromise.
  • Arbitrary code execution.
  • Full system control.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability, which allows unauthenticated remote attackers to achieve full device compromise via unsafe sscanf calls, likely impacts WAGO devices managed by industrial control system (ICS) or operational technology (OT) teams, as well as potentially the IT infrastructure and security teams responsible for network segmentation and external-facing devices. The first actionable step is to identify all deployed instances of the affected WAGO devices, confirm their network exposure and business criticality, and then engage the responsible asset owner to plan a risk-based remediation strategy.

  • Identify and engage affected teams.
  • Verify device exposure and criticality.
  • Plan risk-based remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the WAGO 0852-1322 and 0852-1328 series?

These are industrial networking switches used to connect devices within operational technology (OT) and control network environments. They are specialized components designed to handle reliable data communication for critical infrastructure and industrial automation systems.

What does CVE-2025-41730 mean for device security?

This vulnerability involves a stack-based buffer overflow, categorized as CWE-121 and CWE-787. It occurs because the software uses an unsafe function to process account data, allowing an attacker to overwrite memory. Because the buffer has a fixed size, providing too much data crashes or redirects the device's logic, leading to full system compromise.

How does an attacker trigger this buffer overflow?

An unauthenticated attacker exploits the flaw by sending specially crafted input to the device, which the check_account() function then processes using an unsafe sscanf call. The bug is triggered when this input exceeds the memory allocated for the stack buffer. Normal, valid account management traffic does not trigger this vulnerability.

Is my device at risk if it is on an internal network?

According to Halo Surface Signal, these switches are typically meant for internal or OT environments. While internet-exposed devices face the highest risk, any device reachable by an attacker on your network is vulnerable. You should treat these switches as high-priority assets if they are accessible from untrusted segments.

What is the first step to address this CVE?

Your priority is to audit your environment to locate all instances of the affected WAGO switch models. Once identified, confirm if these devices are visible to external networks or unauthorized segments. After assessing your exposure and business criticality, coordinate with your OT or network security teams to schedule firmware updates to version 02.64 or later.

References