VYPR

managed switches

by Wago

CVEs (7)

  • CVE-2021-20998CriMay 13, 2021
    risk 0.65cvss 10.0epss 0.01

    In multiple managed switches by WAGO in different versions without authorization and with specially crafted packets it is possible to create users.

  • CVE-2025-41732CriDec 10, 2025
    risk 0.64cvss 9.8epss 0.00

    An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_cookie() function to write arbitrary data into fixed-size stack buffers which leads to full device compromise.

  • CVE-2025-41730CriDec 10, 2025
    risk 0.64cvss 9.8epss 0.00

    An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_account() function to write arbitrary data into fixed-size stack buffers which leads to full device compromise.

  • CVE-2021-20994HigMay 13, 2021
    risk 0.57cvss 8.8epss 0.01

    In multiple managed switches by WAGO in different versions an attacker may trick a legitimate user to click a link to inject possible malicious code into the Web-Based Management.

  • CVE-2021-20996MedMay 13, 2021
    risk 0.35cvss 5.3epss 0.01

    In multiple managed switches by WAGO in different versions special crafted requests can lead to cookies being transferred to third parties.

  • CVE-2021-20993MedMay 13, 2021
    risk 0.35cvss 5.3epss 0.01

    In multiple managed switches by WAGO in different versions the activated directory listing provides an attacker with the index of the resources located inside the directory.

  • CVE-2021-20995MedMay 13, 2021
    risk 0.34cvss 5.3epss 0.01

    In multiple managed switches by WAGO in different versions the webserver cookies of the web based UI contain user credentials.