Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-25264— Overly Permissive CORS Policy in WAGO Device Manager

CVSS 6.5 · Medium EPSS 0.13% · P32
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-25264

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Overly Permissive CORS Policy in WAGO Device Manager
Source: NVD (National Vulnerability Database)
Vulnerability Description
An unauthenticated remote attacker can trick an admin to visit a website containing malicious java script code. The current overly permissive CORS policy allows the attacker to obtain any files from the file system.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
过度许可的跨域白名单
Source: NVD (National Vulnerability Database)
Vulnerability Title
WAGO Device Manager 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
WAGO Device Manager是德国万可(WAGO)公司的。 WAGO Device Manager存在安全漏洞,该漏洞源于当前过于宽松的CORS策略,可能导致敏感数据泄露。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
WAGOCC100 0751-9x01 0.0.0 ~ 04.07.01 (FW29) -
WAGOCC100 0751-9x01 0.0.0 ~ 04.07.01 (70 -
WAGOPFC100 G1 0750-810x/xxxx-xxxx 0.0.0 ~ 3.10.11 (FW22 Patch 2) -
WAGOPFC100 G2 0750-811x-xxxx-xxxx 0.0.0 ~ 04.07.01 (70) -
WAGOPFC200 G1 750-820x-xxx-xxx 0.0.0 ~ 3.10.11 (FW22 Patch 2) -
WAGOPFC200 G2 750-821x-xxx-xxx 0.0.0 ~ 04.07.01 (FW29) -
WAGOPFC200 G2 750-821x-xxx-xxx 0.0.0 ~ 04.07.01 (70) -
WAGOTP600 0762-420x/8000-000x 0.0.0 ~ 04.07.01 (FW29) -
WAGOTP600 0762-420x/8000-000x 0.0.0 ~ 04.07.01 (70) -
WAGOTP600 0762-430x/8000-000x 0.0.0 ~ 04.07.01 (FW29) -
WAGOTP600 0762-430x/8000-000x 0.0.0 ~ 04.07.01 (70) -
WAGOTP600 0762-520x/8000-000x 0.0.0 ~ 04.07.01 (FW29) -
WAGOTP600 0762-520x/8000-000x 0.0.0 ~ 04.07.01 (70) -
WAGOTP600 0762-530x/8000-000x 0.0.0 ~ 04.07.01 (FW29) -
WAGOTP600 0762-530x/8000-000x 0.0.0 ~ 04.07.01 (70) -
WAGOTP600 0762-620x/8000-000x 0.0.0 ~ 04.07.01 (FW29) -
WAGOTP600 0762-620x/8000-000x 0.0.0 ~ 04.07.01 (70) -
WAGOTP600 0762-630x/8000-000x 0.0.0 ~ 04.07.01 (FW29) -
WAGOTP600 0762-630x/8000-000x 0.0.0 ~ 04.07.01 (70) -
WAGOEdge Controller 0752-8303/8000-0002 0.0.0 ~ 04.07.01 (FW29) -
WAGOEdge Controller 0752-8303/8000-0002 0.0.0 ~ 04.07.01 (70) -

II. Public POCs for CVE-2025-25264

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-25264

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2025-25264

No comments yet


Leave a comment