CVE-2026-3587 PUBLISHED

Hidden CLI Function Allows Root Access

Assigner: CERTVDE
Reserved: 05.03.2026 Published: 23.03.2026 Updated: 23.03.2026

An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface and gain root access to the underlying Linux based OS, leading to full compromise of the device.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 10

Product Status

Vendor WAGO
Product Lean Managed Switch 852-1812
Versions Default: unaffected
  • affected from 0.0.0 to V1.2.1.S0 (excl.)
Vendor WAGO
Product Lean Managed Switch 852-1813
Versions Default: unaffected
  • affected from 0.0.0 to V1.2.1.S0 (excl.)
Vendor WAGO
Product Lean Managed Switch 852-1813-000-001
Versions Default: unaffected
  • affected from 0.0.0 to V1.2.3.S0 (excl.)
Vendor WAGO
Product Lean Managed Switch 852-1816
Versions Default: unaffected
  • affected from 0.0.0 to V1.2.1.S0 (excl.)
Vendor WAGO
Product Industrial Managed Switch 852-303
Versions Default: unaffected
  • affected from 0.0.0 to V1.2.8.S0 (excl.)
Vendor WAGO
Product Industrial Managed Switch 852-1305
Versions Default: unaffected
  • affected from 0.0.0 to V1.2.0.S0 (excl.)
Vendor WAGO
Product Industrial Managed Switch 852-1305-000-001
Versions Default: unaffected
  • affected from 0.0.0 to V1.2.0.S0 (excl.)
Vendor WAGO
Product Industrial Managed Switch 852-1505-000-001
Versions Default: unaffected
  • affected from 0.0.0 to V1.2.0.S0 (excl.)
Vendor WAGO
Product Industrial Managed Switch 852-1505
Versions Default: unaffected
  • affected from 0.0.0 to V1.1.9.S0 (excl.)
Vendor WAGO
Product Industrial Managed Switch 852-602
Versions Default: unaffected
  • affected from 0.0.0 to V1.0.6.S0 (excl.)
Vendor WAGO
Product Industrial Managed Switch 852-603
Versions Default: unaffected
  • affected from 0.0.0 to V1.0.6.S0 (excl.)
Vendor WAGO
Product Industrial Managed Switch 852-1605
Versions Default: unaffected
  • affected from 0.0.0 to V1.2.5.S0 (excl.)
Vendor WAGO
Product Lean Managed Switch 852-1812-010-000
Versions Default: unaffected
  • affected from 0.0.0 to V1.2.1.S0 (excl.)
Vendor WAGO
Product Lean Managed Switch 852-1813-010-000
Versions Default: unaffected
  • affected from 0.0.0 to V1.2.1.S0 (excl.)
Vendor WAGO
Product Lean Managed Switch 852-1816-010-000
Versions Default: unaffected
  • affected from 0.0.0 to V1.2.1.S0 (excl.)
Vendor WAGO
Product Lean Managed Switch 852-1813/010-001
Versions Default: unaffected
  • affected from 0.0.0 to V1.2.1.S0 (excl.)

References

Problem Types

  • CWE-912 Hidden Functionality CWE