Back to overview

CVE-2022-50926

CRITICAL
9.8
CVSS 3.1
Description
WAGO 750-8212 PFC200 G2 2ETH RS firmware contains a privilege escalation vulnerability that allows attackers to manipulate user session cookies. Attackers can modify the cookie's 'name' and 'roles' parameters to elevate from ordinary user to administrative privileges without authentication.

Metadata

CVE ID
CVE-2022-50926
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-01-11 13:34 UTC
Published
2026-01-13 22:51 UTC
Last updated
2026-01-14 19:19 UTC
Primary CWE
CWE-565
Reliance on Cookies without Validation and Integrity Checkin…
Vendor / Product
Wago / WAGO 750-8212 PFC200
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Wago WAGO 750-8212 PFC200 Firmware version 03.05.10(17)
Weakness (CWE)
CWESourceDescription
CWE-565 cna Reliance on Cookies without Validation and Integrity Checking
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
8.7 HIGH 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
References (3)
Back to overview