CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

pepperl-fuchs

wha-gw-f2d2-0-as-z2-eth.eip_firmware

6 known vulnerabilities · sorted by CVSS score

CVE-2021-34565
CRITICAL9.8

In PEPPERL+FUCHS WirelessHART-Gateway 3.0.7 to 3.0.9 the SSH and telnet services are active with hard-coded credentials.

pepperl-fuchs / wha-gw-f2d2-0-as-z2-eth_firmware+1
Network
Published Aug 31, 2021
CVE-2021-34561
HIGH7.5

In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 serious issue exists, if the application is not externally accessible or uses IP-based access restrictions. Attackers can use DNS Rebinding to bypass any IP or firewall based access restrictions that may be in place, by proxying through their target's browser.

pepperl-fuchs / wha-gw-f2d2-0-as-z2-eth_firmware+1
Network
Published Aug 31, 2021
CVE-2021-34560
MEDIUM5.5

In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored credentials can be captured by an attacker who gains control over the user's computer. Therefore the user must have logged in at least once.

pepperl-fuchs / wha-gw-f2d2-0-as-z2-eth_firmware+1
Local
Published Aug 31, 2021
CVE-2021-34562
MEDIUM5.4

In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 it is possible to inject arbitrary JavaScript into the application's response.

pepperl-fuchs / wha-gw-f2d2-0-as-z2-eth_firmware+1
Network
Published Aug 31, 2021
CVE-2021-34559
MEDIUM5.4

In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 a vulnerability may allow remote attackers to rewrite links and URLs in cached pages to arbitrary strings.

pepperl-fuchs / wha-gw-f2d2-0-as-z2-eth_firmware+1
Network
Published Aug 31, 2021
CVE-2021-34563
LOW3.3

In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 and 3.0.9 the HttpOnly attribute is not set on a cookie. This allows the cookie's value to be read or set by client-side JavaScript.

pepperl-fuchs / wha-gw-f2d2-0-as-z2-eth_firmware+3
Local
Published Aug 31, 2021