CVE-2025-41753 PUBLISHED

Path traversal in dynamically created BACnet File Objects

Assigner: CERTVDE
Reserved: 16.04.2025 Published: 01.10.2026 Updated: 01.10.2026

The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor WAGO
Product 0751-9x01
Versions Default: unaffected
  • affected from 1.0.0 to 4.8.9 (excl.)
Vendor WAGO
Product 0750-811x-xxxx-xxxx
Versions Default: unaffected
  • affected from 1.0.0 to 4.8.9 (excl.)
Vendor WAGO
Product 0750-821x-xxx-xxx
Versions Default: unaffected
  • affected from 1.0.0 to 4.8.9 (excl.)
Vendor WAGO
Product 0762-420x-8000-000x
Versions Default: unaffected
  • affected from 1.0.0 to 4.8.9 (excl.)
Vendor WAGO
Product 0762-430x-8000-000x
Versions Default: unaffected
  • affected from 1.0.0 to 4.8.9 (excl.)
Vendor WAGO
Product 0762-520x-8000-000x
Versions Default: unaffected
  • affected from 1.0.0 to 4.8.9 (excl.)
Vendor WAGO
Product 0762-530x-8000-000x
Versions Default: unaffected
  • affected from 1.0.0 to 4.8.9 (excl.)
Vendor WAGO
Product 0762-620x-8000-000x
Versions Default: unaffected
  • affected from 1.0.0 to 4.8.9 (excl.)
Vendor WAGO
Product 0762-630x-8000-000x
Versions Default: unaffected
  • affected from 1.0.0 to 4.8.9 (excl.)
Vendor WAGO
Product 0752-8303-8000-0002
Versions Default: unaffected
  • affected from 1.0.0 to 4.8.9 (excl.)
Vendor WAGO
Product 0762-340x
Versions Default: unaffected
  • affected from 1.0.0 to 4.8.9 (excl.)
Vendor WAGO
Product 0751-9x01
Versions Default: unaffected
  • affected from 1.0.0 to 4.8.9 (70) (excl.)
Vendor WAGO
Product 0750-811x-xxxx-xxxx
Versions Default: unaffected
  • affected from 1.0.0 to 4.8.9 (70) (excl.)
Vendor WAGO
Product 0750-821x-xxx-xxx
Versions Default: unaffected
  • affected from 1.0.0 to 4.8.9 (70) (excl.)
Vendor WAGO
Product 0762-420x-8000-000x
Versions Default: unaffected
  • affected from 1.0.0 to 4.8.9 (70) (excl.)
Vendor WAGO
Product 0762-430x-8000-000x
Versions Default: unaffected
  • affected from 1.0.0 to 4.8.9 (70) (excl.)
Vendor WAGO
Product 0762-520x-8000-000x
Versions Default: unaffected
  • affected from 1.0.0 to 4.8.9 (70) (excl.)
Vendor WAGO
Product 0762-530x-8000-000x
Versions Default: unaffected
  • affected from 1.0.0 to 4.8.9 (70) (excl.)
Vendor WAGO
Product 0762-620x-8000-000x
Versions Default: unaffected
  • affected from 1.0.0 to 4.8.9 (70) (excl.)
Vendor WAGO
Product 0762-630x-8000-000x
Versions Default: unaffected
  • affected from 1.0.0 to 4.8.9 (70) (excl.)
Vendor WAGO
Product 0752-8303-8000-0002
Versions Default: unaffected
  • affected from 1.0.0 to 4.8.9 (70) (excl.)
Vendor WAGO
Product 0762-340x
Versions Default: unaffected
  • affected from 1.0.0 to 4.8.9 (70) (excl.)

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE