VYPR
High severity7.2NVD Advisory· Published Mar 11, 2020· Updated Jun 17, 2026

CVE-2019-5156

CVE-2019-5156

Description

An exploitable command injection vulnerability exists in the cloud connectivity functionality of WAGO PFC200 versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). An attacker can inject operating system commands into the TimeoutPrepared parameter value contained in the firmware update command.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:o:wago:pfc200_firmware:03.00.39\(12\):*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:o:wago:pfc200_firmware:03.00.39\(12\):*:*:*:*:*:*:*
    • cpe:2.3:o:wago:pfc200_firmware:03.01.07\(13\):*:*:*:*:*:*:*
    • cpe:2.3:o:wago:pfc200_firmware:03.02.02\(14\):*:*:*:*:*:*:*
    • (no CPE)range: version 03.02.02(14)
  • Wago/PFC200llm-fuzzy
    Range: 03.02.02(14), 03.01.07(13), and 03.00.39(12)

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.