CVE-2025-41753 is a critical path traversal flaw in multiple WAGO controller product lines: an unauthenticated remote attacker can read or overwrite arbitrary files on the device through the name of a BACnet File Object.
What Is It
The vulnerability is in how affected WAGO devices handle dynamically created BACnet File Objects. The device treats the object name as a file path and does not validate it well enough. Relative paths are not confined to the intended directory, so an attacker can traverse outside it. CERT@VDE reported the issue and NVD published it on 2026-10-01. Its NVD status is "Awaiting Analysis."
Why It Matters
- No authentication or user interaction required: The attacker needs only network access to the device.
- Arbitrary file read and write: An attacker can read or overwrite files on the device, which the record says "may lead to full system compromise."
- Critical severity: CERT@VDE scores it CVSS 4.0 9.3: network attack vector, low complexity, no privileges required, and high confidentiality, integrity and availability impact. The parsed NVD data also lists a CVSS 3.1 score of 9.8 (
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). - Exploitation status: The supplied CISA KEV data contains no entry for this CVE. Active exploitation is not confirmed by KEV at this time.
What's Vulnerable
The CVE record lists these WAGO products as affected from version 1.0.0 up to, but not including, 4.8.9. A second set of entries puts the upper bound at 4.8.9 (70).
- 0751-9x01
- 0750-811x-xxxx-xxxx
- 0750-821x-xxx-xxx
- 0752-8303-8000-0002
- 0762-340x
- 0762-420x-8000-000x
- 0762-430x-8000-000x
- 0762-520x-8000-000x
- 0762-530x-8000-000x
- 0762-620x-8000-000x
- 0762-630x-8000-000x
The record does not list any affected CPEs.
Patch Status
The affected range ends below version 4.8.9 (70), which suggests that build is the fixed boundary. The supplied data does not explicitly name a fixed release, and CISA has published no required action because there is no KEV listing. Operators of the listed WAGO devices should check CERT@VDE advisory VDE-2025-102 for vendor-confirmed fixed firmware and remediation guidance. They should also confirm their firmware version against the affected ranges above.
Sources
- CERT@VDE Advisory VDE-2025-102
- NVD, CVE-2025-41753
- CISA Known Exploited Vulnerabilities Catalog (no entry for this CVE as of publication)