VYPR
High severity7.2NVD Advisory· Published Mar 11, 2020· Updated Jun 17, 2026

CVE-2019-5157

CVE-2019-5157

Description

An exploitable command injection vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 Firmware versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). An attacker can inject OS commands into the TimeoutUnconfirmed parameter value contained in the Firmware Update command.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:o:wago:pfc200_firmware:03.00.39\(12\):*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:o:wago:pfc200_firmware:03.00.39\(12\):*:*:*:*:*:*:*
    • cpe:2.3:o:wago:pfc200_firmware:03.01.07\(13\):*:*:*:*:*:*:*
    • cpe:2.3:o:wago:pfc200_firmware:03.02.02\(14\):*:*:*:*:*:*:*
    • (no CPE)range: 03.02.02(14), 03.01.07(13), and 03.00.39(12)
    • (no CPE)range: version 03.02.02(14)

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.