Back to overview

CVE-2026-3587

CRITICAL
10.0
CVSS 3.1
Description
An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, leading to full compromise of the device.

Metadata

CVE ID
CVE-2026-3587
State
PUBLISHED
Assigner
CERTVDE
Reserved
2026-03-05 09:44 UTC
Published
2026-03-23 07:49 UTC
Last updated
2026-03-24 07:38 UTC
Primary CWE
CWE-912
CWE-912 Hidden Functionality
Vendor / Product
WAGO / Lean Managed Switch 852-1812
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (16)
VendorProductPlatformVersions
WAGO Industrial Managed Switch 852-1305 0.0.0 < V1.2.0.S0
WAGO Industrial Managed Switch 852-1305-000-001 0.0.0 < V1.2.0.S0
WAGO Industrial Managed Switch 852-1505 0.0.0 < V1.1.9.S0
WAGO Industrial Managed Switch 852-1505-000-001 0.0.0 < V1.2.0.S0
WAGO Industrial Managed Switch 852-1605 0.0.0 < V1.2.5.S0
WAGO Industrial Managed Switch 852-303 0.0.0 < V1.2.8.S0
WAGO Industrial Managed Switch 852-602 0.0.0 < V1.0.6.S0
WAGO Industrial Managed Switch 852-603 0.0.0 < V1.0.6.S0
WAGO Lean Managed Switch 852-1812 0.0.0 < V1.2.1.S0
WAGO Lean Managed Switch 852-1812-010-000 0.0.0 < V1.2.1.S0
WAGO Lean Managed Switch 852-1813 0.0.0 < V1.2.1.S0
WAGO Lean Managed Switch 852-1813-000-001 0.0.0 < V1.2.3.S0
WAGO Lean Managed Switch 852-1813-010-000 0.0.0 < V1.2.1.S0
WAGO Lean Managed Switch 852-1813/010-001 0.0.0 < V1.2.1.S0
WAGO Lean Managed Switch 852-1816 0.0.0 < V1.2.1.S0
WAGO Lean Managed Switch 852-1816-010-000 0.0.0 < V1.2.1.S0
Weakness (CWE)
CWESourceDescription
CWE-912 cna CWE-912 Hidden Functionality
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview