Description

An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management interface of a WAGO PLC. If user-defined scripts are permitted, OpenVPN may allow the execution of arbitrary shell commands enabling the attacker to run arbitrary commands on the device.

INFO

Published Date :

2026-04-09T10:52:41.174Z

Last Modified :

2026-04-09T16:15:38.524Z

Source :

CERTVDE
AFFECTED PRODUCTS

The following products are affected by CVE-2024-1490 vulnerability.

Vendors Products
Wago
  • Cc100 (0751-9x01)
  • Edge Controller (0752-8303-8000-0002)
  • Pfc100 G1 (0750-810-xxxx-xxxx)
  • Pfc100 G2 (0750-811x-xxxx-xxxx)
  • Pfc200 G1 (750-820x-xxxx-xxxx)
  • Pfc200 G2 (750-821x-xxxx-xxxx)
  • Tp600 (0762-420x-8000-000x)
  • Tp600 (0762-430x-8000-000x)
  • Tp600 (0762-520x-8000-000x)
  • Tp600 (0762-530x-8000-000x)
  • Tp600 (0762-620x-8000-000x)
  • Tp600 (0762-630x-8000-000x)
  • Wp400 (0762-340x)
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-1490.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact