CVE-2025-41753: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in WAGO 0751-9x01
The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise.
AI Analysis
Technical Summary
This vulnerability involves improper limitation of a pathname to a restricted directory (CWE-22) in WAGO 0751-9x01. The device interprets the object name of a dynamically created BACnet File Object as a file path without sufficient validation, enabling an unauthenticated remote attacker to perform path traversal attacks. By exploiting this, the attacker can access or modify files outside the intended directory, which may result in full system compromise. The CVSS 4.0 base score is 9.3, indicating critical severity with network attack vector, no required privileges or user interaction, and high impact on confidentiality, integrity, and availability.
Potential Impact
An unauthenticated remote attacker can read or overwrite arbitrary files on the affected device by exploiting the path traversal vulnerability. This can lead to full system compromise, affecting confidentiality, integrity, and availability of the device and its data.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch links are provided in the available data. Until a patch is available, restrict network access to the device and monitor for suspicious activity related to BACnet File Object manipulation.
CVE-2025-41753: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in WAGO 0751-9x01
Description
The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise.
CVSS v4.0
Score 9.3critical
Affected software
WAGO
0751-9x01
WAGO
0750-811x-xxxx-xxxx
WAGO
0750-821x-xxx-xxx
WAGO
0762-420x-8000-000x
WAGO
0762-430x-8000-000x
WAGO
0762-520x-8000-000x
WAGO
0762-530x-8000-000x
WAGO
0762-620x-8000-000x
WAGO
0762-630x-8000-000x
WAGO
0752-8303-8000-0002
WAGO
0762-340x
WAGO
0751-9x01
WAGO
0750-811x-xxxx-xxxx
WAGO
0750-821x-xxx-xxx
WAGO
0762-420x-8000-000x
WAGO
0762-430x-8000-000x
WAGO
0762-520x-8000-000x
WAGO
0762-530x-8000-000x
WAGO
0762-620x-8000-000x
WAGO
0762-630x-8000-000x
WAGO
0752-8303-8000-0002
WAGO
0762-340x
pkg:github/wago/0751-9x01Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves improper limitation of a pathname to a restricted directory (CWE-22) in WAGO 0751-9x01. The device interprets the object name of a dynamically created BACnet File Object as a file path without sufficient validation, enabling an unauthenticated remote attacker to perform path traversal attacks. By exploiting this, the attacker can access or modify files outside the intended directory, which may result in full system compromise. The CVSS 4.0 base score is 9.3, indicating critical severity with network attack vector, no required privileges or user interaction, and high impact on confidentiality, integrity, and availability.
Potential Impact
An unauthenticated remote attacker can read or overwrite arbitrary files on the affected device by exploiting the path traversal vulnerability. This can lead to full system compromise, affecting confidentiality, integrity, and availability of the device and its data.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch links are provided in the available data. Until a patch is available, restrict network access to the device and monitor for suspicious activity related to BACnet File Object manipulation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CERTVDE
- Date Reserved
- 2025-04-16T11:18:45.759Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abe749ca43b0b3b89bd1d5c
Added to database: 10/01/2026, 14:56:28 UTC
Last enriched: 10/01/2026, 15:28:05 UTC
Last updated: 10/02/2026, 02:42:17 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.