# Critical CVSS 10.0 Flaw in WAGO Industrial Managed Switches Allows Full Device Takeover


## The Threat


CISA has published an advisory for CVE-2026-3587, a maximum-severity vulnerability (CVSS 3.1: 10.0 CRITICAL) affecting WAGO GmbH & Co. KG Industrial Managed Switches. An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, leading to full compromise of the device.


The vulnerability is classified under CWE-912: Hidden Functionality — meaning the affected devices contain undocumented functionality that was never intended to be accessible, but can be reached remotely without any credentials.


## Severity and Impact


| Metric | Value |

|--------|-------|

| CVE | CVE-2026-3587 |

| CVSS 3.1 | 10.0 — CRITICAL |

| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |

| Attack Complexity | Low |

| Authentication | None required |

| Impact | Full device compromise |


The perfect 10.0 score reflects that this vulnerability requires no authentication, no user interaction, is remotely exploitable with low complexity, and results in complete confidentiality, integrity, and availability impact with scope change.


## Affected Products


Over 30 firmware/hardware combinations are impacted across two product families:


Lean Managed Switches (vulnerable firmware → fixed version):

  • 852-1812: prior to V1.2.1.S0 → V1.2.1.S1
  • 852-1812/010-000: prior to V1.2.1.S0 → V1.2.1.S1
  • 852-1813: prior to V1.2.1.S0 → V1.2.1.S1
  • 852-1813/000-001: prior to V1.2.3.S0 → V1.2.3.S1
  • 852-1813/010-000: prior to V1.2.1.S0 → V1.2.1.S1
  • 852-1813/010-001: V1.2.1.S0 → V1.2.1.S1
  • 852-1816: prior to V1.2.1.S0 → V1.2.1.S1
  • 852-1816/010-000: prior to V1.2.1.S0 → V1.2.1.S1

  • Industrial Managed Switches (vulnerable firmware → fixed version):

  • 852-303: prior to V1.2.8.S0 → V1.2.8.S1
  • 852-602: prior to V1.0.6.S0 → V1.0.6.S1
  • 852-603: prior to V1.0.6.S0 → V1.0.6.S1
  • 852-1305: prior to V1.2.0.S0 → V1.2.0.S1
  • 852-1305/000-001: prior to V1.2.0.S0 → V1.2.0.S1
  • 852-1505: prior to V1.1.9.S0 → V1.1.9.S1
  • 852-1505/000-001: prior to V1.2.0.S0 → V1.2.0.S1
  • 852-1605: prior to V1.2.5.S0 → V1.2.5.S1

  • ## Critical Infrastructure Exposure


    These devices are deployed worldwide across multiple critical infrastructure sectors:


  • Commercial Facilities
  • Critical Manufacturing
  • Energy
  • Transportation Systems

  • WAGO is headquartered in Germany and is a major supplier of industrial automation components.


    ## Mitigations


    WAGO recommends the following actions:


    1. Update firmware immediately to the fixed versions listed above

    2. Deactivate SSH and Telnet on Lean Managed Switches (852-1812, 852-1813, 852-1816 families) to eliminate the remote attack vector

    3. Deactivate SSH and Telnet on Industrial Managed Switches (852-303, 852-1305, 852-1505, 852-602, 852-603, 852-1605) — this limits CLI access to local RS232 only


    CISA additionally recommends:


  • Minimize network exposure for all control system devices — do not make them internet-accessible
  • Isolate control networks behind firewalls, separated from business networks
  • Use VPNs for remote access, kept updated to the latest version
  • Perform impact analysis and risk assessment before deploying defensive measures

  • ## References


  • [CISA Advisory ICSA-26-085-01](https://www.cisa.gov/news-events/ics-advisories/icsa-26-085-01)
  • [WAGO PSIRT](https://www.wago.com/de-en/automation-technology/psirt)
  • [VDE-2026-020 Advisory](https://certvde.com/en/advisories/VDE-2026-020)

  • No known public exploitation targeting this vulnerability has been reported to CISA at this time. The advisory was initially published on March 26, 2026, as a republication of WAGO's VDE-2026-020.