# Critical CVSS 10.0 Flaw in WAGO Industrial Managed Switches Allows Full Device Takeover
## The Threat
CISA has published an advisory for CVE-2026-3587, a maximum-severity vulnerability (CVSS 3.1: 10.0 CRITICAL) affecting WAGO GmbH & Co. KG Industrial Managed Switches. An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, leading to full compromise of the device.
The vulnerability is classified under CWE-912: Hidden Functionality — meaning the affected devices contain undocumented functionality that was never intended to be accessible, but can be reached remotely without any credentials.
## Severity and Impact
| Metric | Value |
|--------|-------|
| CVE | CVE-2026-3587 |
| CVSS 3.1 | 10.0 — CRITICAL |
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Attack Complexity | Low |
| Authentication | None required |
| Impact | Full device compromise |
The perfect 10.0 score reflects that this vulnerability requires no authentication, no user interaction, is remotely exploitable with low complexity, and results in complete confidentiality, integrity, and availability impact with scope change.
## Affected Products
Over 30 firmware/hardware combinations are impacted across two product families:
Lean Managed Switches (vulnerable firmware → fixed version):
Industrial Managed Switches (vulnerable firmware → fixed version):
## Critical Infrastructure Exposure
These devices are deployed worldwide across multiple critical infrastructure sectors:
WAGO is headquartered in Germany and is a major supplier of industrial automation components.
## Mitigations
WAGO recommends the following actions:
1. Update firmware immediately to the fixed versions listed above
2. Deactivate SSH and Telnet on Lean Managed Switches (852-1812, 852-1813, 852-1816 families) to eliminate the remote attack vector
3. Deactivate SSH and Telnet on Industrial Managed Switches (852-303, 852-1305, 852-1505, 852-602, 852-603, 852-1605) — this limits CLI access to local RS232 only
CISA additionally recommends:
## References
No known public exploitation targeting this vulnerability has been reported to CISA at this time. The advisory was initially published on March 26, 2026, as a republication of WAGO's VDE-2026-020.