CVE-2026-22905 | WAGO 0852-1322/0852-1328 up to 2.64 CGI Endpoint /js/../cgi-bin/post.cgi path traversal (VDE-2026-004)
A vulnerability described as critical has been identified in WAGO 0852-1322 and 0852-1328 up to 2.64. Affected by this issue is some unknown functionality of the file /js/../cgi-bin/post.cgi of the component CGI Endpoint. Such manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2026-22905. The attack can be launched remotely. No exploit exists.