External risk intelligence

Wago Device Stack Buffer Overflow Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-41732

The affected products are industrial network switches. While they possess network-accessible interfaces, these devices are typically deployed within internal operational technology (OT) networks or isolated management segments rather than being exposed directly to the public internet in common deployments.

Out-of-bounds Write

Wago 0852 1328 Firmware

before 02.64

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability allows an unauthenticated attacker to remotely compromise devices by exploiting a weakness in how certain software handles data. The potential impact is severe, as it could lead to a full device takeover, affecting the confidentiality, integrity, and availability of the system. The primary concern at this stage is to determine if any of the affected industrial network switches are exposed in a way that would make them vulnerable.

  • Unauthenticated attackers can take full control of devices.
  • Vulnerable devices are industrial network switches.
  • Confirm if affected industrial switches are exposed externally.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted network traffic to the affected device. This traffic targets the `check_cookie()` function, which uses unsafe `sscanf` calls. If successful, the attacker can overwrite critical data on the device's stack, potentially leading to complete control of the system.

  • Requires network access.
  • Triggers unsafe `sscanf` in `check_cookie()`.
  • Leads to full device compromise.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated remote attacker could exploit a vulnerability in the check_cookie() function by abusing unsafe sscanf calls. This could allow them to write arbitrary data into fixed-size stack buffers, potentially leading to a full device compromise.

  • Device integrity and availability at risk.
  • Arbitrary data writes to stack buffers.
  • Full device compromise possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in WAGO 0852 series firmware allows unauthenticated attackers to achieve full device compromise by exploiting unsafe sscanf calls. Identifying and securing these industrial network switches, typically found in OT environments, is paramount. Ownership likely falls to industrial control system (ICS) or operational technology (OT) teams, with coordination from network and security teams. The immediate priority is to locate all instances of the affected devices, assess their network exposure, and confirm business criticality before planning remediation, potentially involving vendor engagement for firmware updates.

  • ICS/OT teams own the issue.
  • Verify device reachability and criticality.
  • Plan vendor-coordinated remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the WAGO 0852 series?

These are industrial network switches used to connect and manage communication between machines and controllers in factory settings and operational technology (OT) environments. They form the underlying connectivity fabric for automated systems.

What does CWE-121 and CWE-787 mean for CVE-2025-41732?

These codes identify a stack-based buffer overflow. In plain terms, the software lacks proper safeguards when writing incoming data into its memory. An attacker can exploit this by sending more data than the memory space can hold, causing it to spill over and overwrite critical system instructions.

How can an attacker trigger this vulnerability?

An attacker needs to send specific, malicious network traffic that reaches the device's check_cookie() function. The vulnerability is triggered solely by this interaction with the unsafe sscanf processing; it does not require the attacker to have pre-existing credentials or special user permissions to initiate.

Do I need to worry about this if my device is on a private network?

Halo Surface Signal notes that while these switches are network-accessible, they are often placed in isolated management segments or internal OT networks. Because the threat requires network reachability, devices not exposed to the public internet have a reduced immediate attack surface, though internal security remains vital.

When should I prioritize patching these switches?

Prioritize patching immediately by identifying all affected 0852-1322 and 0852-1328 models in your inventory. Work with your OT and ICS teams to assess their network accessibility, then coordinate with the vendor to apply the necessary firmware updates to move past version 02.64.

References