← Back to browse · API

CVE-2026-3587

Severity
CRITICAL
CVSS
10.0
EPSS
0.00679
Risk score
40.24
CISA KEV
No
PoC
No
Published
2026-03-23
Modified
2026-03-24
First seen
2026-08-07
Aliases
EUVD-2026-14385, GHSA-4R7Q-86HG-H98X
Products
WAGO:Industrial Managed Switch 852-1305 0.0.0 <V1.2.0.S0, WAGO:Industrial Managed Switch 852-1305-000-001 0.0.0 <V1.2.0.S0, WAGO:Industrial Managed Switch 852-1505 0.0.0 <V1.1.9.S0, WAGO:Industrial Managed Switch 852-1505-000-001 0.0.0 <V1.2.0.S0, WAGO:Industrial Managed Switch 852-1605 0.0.0 <V1.2.5.S0, WAGO:Industrial Managed Switch 852-303 0.0.0 <V1.2.8.S0, WAGO:Industrial Managed Switch 852-602 0.0.0 <V1.0.6.S0, WAGO:Industrial Managed Switch 852-603 0.0.0 <V1.0.6.S0, WAGO:Lean Managed Switch 852-1812 0.0.0 <V1.2.1.S0, WAGO:Lean Managed Switch 852-1812-010-000 0.0.0 <V1.2.1.S0, WAGO:Lean Managed Switch 852-1813 0.0.0 <V1.2.1.S0, WAGO:Lean Managed Switch 852-1813-000-001 0.0.0 <V1.2.3.S0, WAGO:Lean Managed Switch 852-1813-010-000 0.0.0 <V1.2.1.S0, WAGO:Lean Managed Switch 852-1813/010-001 0.0.0 <V1.2.1.S0, WAGO:Lean Managed Switch 852-1816 0.0.0 <V1.2.1.S0, WAGO:Lean Managed Switch 852-1816-010-000 0.0.0 <V1.2.1.S0
Sources
euvd EUVD-2026-14385

Description

An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, leading to full compromise of the device.

References