CVE-2020-12522
CVE-2020-12522 is a critical-severity vulnerability in Wago Pfc 100 Firmware with a CVSS 3.x base score of 10.0. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-78.
Key facts
- Severity: Critical (CVSS 3.x base score 10.0)
- CVSS v2: 10.0
- EPSS exploit prediction: 3% (87th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-78
- Affected product: Wago Pfc 100 Firmware
- Published:
- Last modified:
Description
The reported vulnerability allows an attacker who has network access to the device to execute code with specially crafted packets in WAGO Series PFC 100 (750-81xx/xxx-xxx), Series PFC 200 (750-82xx/xxx-xxx), Series Wago Touch Panel 600 Standard Line (762-4xxx), Series Wago Touch Panel 600 Advanced Line (762-5xxx), Series Wago Touch Panel 600 Marine Line (762-6xxx) with firmware versions <=FW10.
Frequently asked questions
- What is CVE-2020-12522?
- The reported vulnerability allows an attacker who has network access to the device to execute code with specially crafted packets in WAGO Series PFC 100 (750-81xx/xxx-xxx), Series PFC 200 (750-82xx/xxx-xxx), Series Wago Touch Panel 600 Standard Line (762-4xxx), Series Wago Touch Panel 600 Advanced Line (762-5xxx), Series Wago Touch Panel 600 Marine Line (762-6xxx) with firmware versions <=FW10.
- How severe is CVE-2020-12522?
- CVE-2020-12522 has a CVSS 3.x base score of 10.0, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2020-12522 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 3% (87th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2020-12522?
- CVE-2020-12522 primarily affects Wago Pfc 100 Firmware. In total, 5 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2020-12522?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2020-12522 published?
- CVE-2020-12522 was published on 2020-12-17 and last updated on 2026-06-17.
References
Affected products (5)
- cpe:2.3:o:wago:pfc_100_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:wago:pfc_200_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:wago:touch_panel_600_standard_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:wago:touch_panel_600_advanced_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:wago:touch_panel_600_marine_firmware:*:*:*:*:*:*:*:*
More vulnerabilities in Wago Pfc 100 Firmware
- CVE-2019-5079 — Critical (CVSS 9.8): An exploitable heap buffer overflow vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO…
- CVE-2019-5075 — Critical (CVSS 9.8): An exploitable stack buffer overflow vulnerability exists in the command line utility getcouplerdetails of WAGO PFC200…
- CVE-2019-5081 — Critical (CVSS 9.8): An exploitable heap buffer overflow vulnerability exists in the iocheckd service ''I/O-Chec'' functionality of WAGO PFC…
- CVE-2019-5074 — Critical (CVSS 9.8): An exploitable stack buffer overflow vulnerability exists in the iocheckd service ''I/O-Check'' functionality of WAGO…
- CVE-2019-5080 — Critical (CVSS 9.1): An exploitable denial-of-service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200…
- CVE-2019-5078 — Critical (CVSS 9.1): An exploitable denial of service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200…
All CVEs affecting Wago Pfc 100 Firmware →
Other CWE-78 (OS Command Injection) vulnerabilities
- CVE-2026-100382 — Critical (CVSS 10.0): Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia…
- CVE-2026-77521 — Critical (CVSS 10.0): MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool,…
- CVE-2026-82004 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS…
- CVE-2026-76197 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS…
- CVE-2026-76195 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS…
- CVE-2026-19188 — Critical (CVSS 10.0): A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The…