---
schema: 1
kind: vulnerability
title: "CVE-2026-4769 — WAGO I/O System Field: undocumented early-boot interface allows unauthenticated full compromise (CVSS 9.8)"
headline: "WAGO patches a hidden early-boot diagnostic interface in I/O System Field couplers that lets an unauthenticated remote attacker take full control"
summary: >
  CERT@VDE published advisory VDE-2026-031 / CVE-2026-4769 (2026-07-13) for WAGO I/O System Field coupler devices: certain models activate an undocumented diagnostic capability during the initial boot sequence that is reachable without authentication for a brief early-boot window, letting an unauthenticated remote attacker with network access reach internal system processes and achieve full system compromise (CWE-912 Hidden Functionality; CVSS 9.8). No exploitation is reported (EPSS 0.0) and fixed firmware is available per model. Swiss/European energy, water and industrial-automation OT estates running these couplers should schedule the firmware update and verify these devices are segmented from untrusted networks, especially during maintenance reboots.
discovered_at: "2026-07-13T12:50:00Z"
event_date: "2026-07-13"
run_id: 2026-07-13T1212Z-intel
priority: notable
immediate_action: null
tags: [vulnerabilities, ot-ics, auth-bypass, pre-auth, patch-available]
regions: [global, europe]
sectors: [energy, water, manufacturing]
entities: []
techniques: [T1190]
affected_products: ["WAGO I/O System Field 0765-110x/0100-0000", "WAGO I/O System Field 0765-120x/0100-0000", "WAGO I/O System Field 0765-150x/0100-0000", "WAGO I/O System Field 0765-2101/0100-0000", "WAGO I/O System Field 0765-2102/0100-0000", "WAGO I/O System Field 0765-410x/0100-0000", "WAGO I/O System Field 0765-420x/0100-0000", "WAGO I/O System Field 0765-450x/0100-0000"]
cves:
  - id: CVE-2026-4769
    cvss: "9.8"
    epss: "0.0"
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "WAGO I/O System Field 0765-110x/120x/150x/210x/2102/410x/420x/450x (variant /0100-0000)"
    fixed: "Per model: 1.2.1.100 (110x/410x); 1.2.7.100 (120x/420x); 1.2.7.103 (150x/450x); 1.2.1.102 (2101); 1.2.5.101 (2102)"
sources:
  - url: "https://www.certvde.com/en/advisories/VDE-2026-031/"
    publisher: "CERT@VDE (Germany OT/ICS coordinating CERT, CNA)"
    date: "2026-07-13"
    role: primary
  - url: "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43297"
    publisher: "ENISA EU Vulnerability Database (EUVD-2026-43297)"
    date: "2026-07-13"
    role: corroborating
closed_sources: []
evidence:
  - quote: "This functionality is not formally documented and becomes accessible without authentication for a brief period in the early boot phase. During this window, an unauthenticated remote attacker can gain access to the internal system processes, resulting in full system compromise."
    publisher: "CERT@VDE"
verification: single-source
sourcing_note: "Single primary: CERT@VDE, Germany's OT/ICS coordinating CERT acting as CVE Numbering Authority for this WAGO advisory (high-reliability, A — the authoritative primary for its own coordinated disclosure). The ENISA EU Vulnerability Database entry (EUVD-2026-43297) republishes the same advisory data rather than corroborating independently, so this is treated as single-source rather than a national-CERT carve-out. No exploitation reported (EPSS 0.0)."
confidence: medium
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 2
watchlist_hit: false
actions: []
migrated_from: null
---

CERT@VDE — Germany's OT/ICS coordinating CERT, acting as CVE Numbering Authority for the vendor — published advisory VDE-2026-031 / CVE-2026-4769 on 2026-07-13 for WAGO I/O System Field series coupler devices (models 0765-110x, 0765-120x, 0765-150x, 0765-2101, 0765-2102, 0765-410x, 0765-420x, 0765-450x, all variant `/0100-0000`) ([CERT@VDE, 2026-07-13](https://www.certvde.com/en/advisories/VDE-2026-031/)). Certain devices activate an undocumented internal diagnostic capability during the initial boot sequence — functionality outside the publicly documented feature set — which is reachable without authentication for a brief window before the main operating environment and its security controls become fully active (CWE-912 Hidden Functionality). If an attacker has network access to the device during that early-boot window, they can interact with internal system processes normally protected during regular operation, which CERT@VDE describes as resulting in full system compromise. The advisory carries a CVSS 3.1 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (9.8), and the ENISA EU Vulnerability Database entry EUVD-2026-43297 lists a CVSS 4.0 base score of 9.3 ([ENISA EUVD, 2026-07-13](https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43297)). No exploitation has been reported and EPSS is 0.0. WAGO has released fixed firmware for each affected model.

WAGO I/O System Field devices are modular fieldbus I/O couplers used in industrial automation and building-management deployments, including energy and water-utility OT environments in the constituency's additional sectors. The practical exploitability is bounded — an attacker must have network reachability to the device precisely during its early-boot window — but the impact if that condition is met is unauthenticated, full compromise of an operational field device, and OT patch cycles are slow, so the exposure can persist. Detection is best framed as OT network monitoring: correlate device power-cycle/reboot events (from maintenance logs or the device's own uptime telemetry) with any new inbound session to the device's management/diagnostic ports in the same time window — a connection arriving during a reboot, rather than steady-state operation, is the anomaly this vulnerability creates. Hardening: apply the per-model fixed firmware listed above and, until then, keep these couplers behind VLAN/ACL segmentation from any untrusted network segment, tightening reachability during planned maintenance reboots when the early-boot window is opened deliberately.
