


Perceptive Security
SOC/SIEM Consultancy

WAGO GmbH & Co. KG Industrial Managed Switches
Published:
26 maart 2026 om 12:00:00
Alert date:
26 maart 2026 om 17:02:46
Source:
cisa.gov
Critical Infrastructure, Network Infrastructure
A critical vulnerability (CVE-2026-3587) with CVSS score 10.0 affects WAGO Industrial Managed Switches across multiple firmware versions. The vulnerability allows unauthenticated remote attackers to exploit a hidden function in the CLI prompt to escape the restricted interface, leading to full device compromise. The flaw impacts critical infrastructure sectors including energy, transportation, and manufacturing. WAGO has released firmware updates to address the vulnerability and recommends disabling SSH/telnet access as a mitigation. No known public exploitation has been reported to CISA at this time.
Technical details
Mitigation steps:
Affected products:
WAGO Industrial Managed Switches
Related links:
https://www.cisa.gov/news-events/ics-advisories/icsa-26-085-01
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-085-01.json
https://www.cve.org/CVERecord?id=CVE-2026-3587
https://www.wago.com/de-en/automation-technology/psirt
https://certvde.com/en/advisories/VDE-2026-020
https://wago.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-020.json
https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
https://cwe.mitre.org/data/definitions/912.html
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
