#VU26273 Regular Expression without Anchors in Wago PFC200 Controller and WAGO PFC100 Controller - CVE-2019-5134
Published: March 20, 2020
Wago PFC200 Controller
WAGO PFC100 Controller
WAGO
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the regular expression without anchors issue in the Web-Based Management (WBM) authentication functionality. A remote attacker can use a specially crafted authentication request to bypass regular expression filters and gain access to sensitive information on the target system.