CVE-2023-1698 is a vulnerability affecting multiple WAGO products that allows an unauthenticated, remote attacker to create new users and modify device configuration. This can be exploited without prior authentication, enabling attackers to gain unauthorized access and control over the device, potentially leading to system misconfiguration, denial of service, or full system compromise.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Go-based exploit for CVE-2023-1698, targeting WAGO industrial controllers (PFC series) via their web management interface. The exploit is operational and provides both single-target and bulk scanning modes. It sends a specially crafted JSON payload to the endpoint '/wbm/plugins/wbm-legal-information/platform/pfcXXX/licenses.php' on the target device, exploiting a vulnerability that allows remote code execution. The payload injects arbitrary shell commands, wrapping the output with unique markers for easy extraction. If a target is found vulnerable, the tool can drop into an interactive shell, allowing the attacker to execute further commands. The code is well-structured, with command-line options for specifying targets, output files, thread count, and custom commands. The README provides usage examples. No hardcoded IPs or domains are present; the user supplies the target(s) via command-line arguments or a file. The exploit is not part of a framework and is a standalone operational tool.
This repository contains a working proof-of-concept (PoC) exploit for CVE-2023-1698, a critical command injection vulnerability affecting WAGO PLC devices. The main exploit script, 'wago_exploit.py', is a Python 3 tool that sends crafted POST requests to a specific endpoint on the target PLC's web interface ('/wbm/plugins/wbm-legal-information/platform/pfcXXX/licenses.php'). The exploit injects shell commands via the 'package' parameter in the JSON body, allowing the attacker to execute arbitrary commands on the device. The script supports interactive shell access, enabling the attacker to run multiple commands after confirming vulnerability. The repository also includes a README.md with usage instructions and a requirements.txt listing dependencies ('requests' and 'colorama'). The exploit is network-based and requires the attacker to have access to the target device's web interface. No hardcoded IPs or credentials are present; the user supplies the target URL. The exploit is classified as a PoC, as it demonstrates the vulnerability and provides interactive command execution but does not include advanced features or automation for mass exploitation.
This repository provides a functional exploit for CVE-2023-1698, a critical unauthenticated remote code execution vulnerability affecting multiple WAGO industrial devices. The main exploit script ('exploit.py') allows users to check single or multiple URLs for vulnerability, execute arbitrary shell commands on compromised devices, and interactively control a vulnerable target. The exploit works by sending a specially crafted POST request to the endpoint '/wbm/plugins/wbm-legal-information/platform/pfcXXX/licenses.php' on the target device, injecting shell commands via the 'package' parameter. The output of the command is extracted from the HTTP response using a specific marker pattern. The tool supports multi-threaded scanning and can save lists of vulnerable URLs. The repository also includes a helper script ('parser_zoomeye.py') for processing ZoomEye search results, which can be used to discover potential targets. The code is written in Python and requires several third-party libraries as specified in 'requirements.txt'. The exploit is operational and provides real command execution capabilities, but is not part of a larger exploitation framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.