CVE-2026-22903 Details
Description
An unauthenticated remote attacker can send a crafted HTTP request containing an overly long SESSIONID cookie. This can trigger a stack buffer overflow in the modified lighttpd server, causing it to crash and potentially enabling remote code execution due to missing stack protections.
A stack buffer overflow vulnerability has been identified in the WAGO Industrial-Managed-Switch models 0852-1322 and 0852-1328, both running firmware through 2.64. An unauthenticated remote attacker can exploit this vulnerability by sending an HTTP request with an excessively long SESSIONID cookie. This exploitation can cause the modified lighttpd server to crash and potentially allow remote code execution, as the stack protections are inadequate.
Users are advised to update their devices to firmware version 02.65.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 9, 2026CISA-ADP
Assessed Feb 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://certvde.com/de/advisories/VDE-2026-004 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| WAGO Industrial-Managed-Switch 0852-1322 | All versions |
CPE
Remediation
| |
| WAGO Industrial-Managed-Switch 0852-1328 | All versions |
CPE
Remediation
| |
| lighttpd | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 9, 2026 | New CVE Received | [email protected] |
Volerion