PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-9362 Wago CVE debrief

CVE-2016-9362 is a critical authentication flaw in the web server of several WAGO controllers. According to the CVE description, an attacker can use a specific URL to view and edit settings without authenticating. The issue was publicly disclosed on 2017-02-13 and carries a CVSS 3.0 score of 9.1.

Vendor
Wago
Product
Unknown
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2016-09-25
Original CVE updated
2025-06-05
Advisory published
2016-09-25
Advisory updated
2025-06-05

Who should care

OT and industrial automation teams running affected WAGO 750-8202/PFC200, 750-881, or 0758-0874-0000-0111 devices should treat this as urgent. Any environment exposing the controller web interface to untrusted networks should prioritize review and remediation.

Technical summary

NVD classifies the weakness as CWE-287 (Improper Authentication) and rates it CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N. That means the flaw is remotely reachable, requires no privileges or user interaction, and can expose confidential settings while allowing integrity-impacting changes. The supplied description indicates affected firmware versions were older than WAGO FW04 for 750-8202/PFC200 and FW09 for 750-881.

Defensive priority

Critical. This is a network-exploitable, unauthenticated access-control failure on an industrial controller web interface with high confidentiality and integrity impact.

Recommended defensive actions

  • Identify whether any WAGO 750-8202/PFC200, 750-881, or 0758-0874-0000-0111 devices are in use.
  • Determine whether the web server management interface is reachable from untrusted or broader-than-necessary network segments.
  • Apply the vendor-referenced firmware updates or later versions corresponding to FW04 or FW09, as applicable to the device.
  • Restrict access to the controller web interface with network controls such as segmentation, allowlists, or jump hosts.
  • Review controller settings for unexpected changes and preserve logs or configuration backups for comparison.
  • If remediation must be delayed, isolate the device and minimize exposure to authenticated administrative paths only.

Evidence notes

The summary is based on the supplied CVE description, which states that a malicious user can access a specific URL on the web server to view and edit settings without authenticating. NVD metadata in the corpus provides the CVSS vector CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N and CWE-287. The linked ICS-CERT advisory reference (ICSA-16-357-02) is included in the source corpus as supporting context.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-9362 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-9362

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-9362 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-9362

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.