Cyber & AI intelligence
Wasteland.
Briefs indexed2957
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2025-41753 2026-10-01

CVE-2025-41753: Unauthenticated Path Traversal in WAGO BACnet File Objects

"CVE-2025-41753 is a critical path traversal flaw in multiple WAGO controller product lines: an unauthenticated remote attacker can read or overwrite arbitrary files on the device through the name of a BACnet File Object."

CVE-2025-41753 is a critical path traversal flaw in multiple WAGO controller product lines: an unauthenticated remote attacker can read or overwrite arbitrary files on the device through the name of a BACnet File Object.

What Is It

The vulnerability is in how affected WAGO devices handle dynamically created BACnet File Objects. The device treats the object name as a file path and does not validate it well enough. Relative paths are not confined to the intended directory, so an attacker can traverse outside it. CERT@VDE reported the issue and NVD published it on 2026-10-01. Its NVD status is "Awaiting Analysis."

Why It Matters

What's Vulnerable

The CVE record lists these WAGO products as affected from version 1.0.0 up to, but not including, 4.8.9. A second set of entries puts the upper bound at 4.8.9 (70).

The record does not list any affected CPEs.

Patch Status

The affected range ends below version 4.8.9 (70), which suggests that build is the fixed boundary. The supplied data does not explicitly name a fixed release, and CISA has published no required action because there is no KEV listing. Operators of the listed WAGO devices should check CERT@VDE advisory VDE-2025-102 for vendor-confirmed fixed firmware and remediation guidance. They should also confirm their firmware version against the affected ranges above.

Sources