S4E just found a high top 10 tcp port service scan
high·Misconfiguration·Updated May 16, 2025

WAGO Web-Based Management Default Login Scanner

This scanner probes WAGO Web-Based Management login endpoints for default username/password combinations, enabling attackers to gain full administrative control over PLCs and automation systems.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.4k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
Detail

WAGO Web-Based Management is a web interface used to configure and monitor WAGO programmable logic controllers (PLCs) and automation systems. It is widely deployed in manufacturing plants, process industries, and commercial building automation. System integrators, engineers, and IT professionals rely on it for real-time system management, diagnostics, and firmware updates.

The vulnerability arises when default credentials (e.g., admin/admin) are left unchanged after initial setup. This common oversight allows attackers to bypass authentication and gain unauthorized access to the management interface. The issue is exacerbated by the fact that many OT environments lack regular security audits, leaving default credentials in place for years.

This scanner specifically targets the login endpoint of WAGO Web-Based Management, typically found at /login or /admin. It tests a list of known default username and password pairs against the interface. If any pair succeeds, the scanner flags the asset as vulnerable, indicating that the interface is accessible with default credentials.

Exploitation of this vulnerability can lead to full control over the WAGO PLC, allowing attackers to modify control logic, disrupt production processes, or exfiltrate sensitive data. In critical infrastructure environments, this could cause operational downtime, safety hazards, or even physical damage. Immediate remediation is essential to protect OT assets.

Solution Advice
  • Change all default credentials immediately upon installation to strong, unique passwords.
  • Implement multi-factor authentication (MFA) for all WAGO Web-Based Management interfaces.
  • Restrict network access to the management interface using firewalls or VLAN segmentation.
  • Conduct regular security audits to identify and remediate unchanged default credentials.
  • Disable unused accounts and remove default guest or test accounts.
  • Enable logging and monitoring to detect unauthorized login attempts.
  • Apply the latest firmware updates from WAGO to patch known vulnerabilities.
  • Use a centralized credential management system to enforce password policies across all OT devices.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

WAGO Web-Based Management Default Login Scanner | S4E Free Check S4E