CVE-2025-1235 - CVE House
Back to Database
Status published Medium CVE-2025-1235

WAGO: Switches affected by year 2k38 problem

Vulnerability Description

A low privileged attacker can set the date of the devices to the 19th of January 2038 an therefore exceed the 32-Bit time limit. This causes the date of the switch to be set back to January 1st, 1970.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-1235

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Marcus Kramhöller from Noris Automatio GmbH

Affected Vendor

Affected Software

Fully Managed Switches 0852-0303, Fully Managed Switches 0852-1305, Fully Managed Switches 0852-1305/0000-0001, Fully Managed Switches 0852-1505, Fully Managed Switches 0852-1505/0000-0001, Lean Managed Switches 0852-1812, Lean Managed Switches 0852-1812/0010-0000, Lean Managed Switches 0852-1813, Lean Managed Switches 0852-1813/0000-0001, Lean Managed Switches 0852-1813/0010-0000, Lean Managed Switches 0852-1813/0010-0001, Lean Managed Switches 0852-1816, Lean Managed Switches 0852-1816/0010-0000
Vulnerable Versions:
all

Timeline

Official Publish: June 2nd, 2025
Last Modified: June 2nd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Weaknesses (CWE)