
Last summer, WAGO Device Sphere shipped every install with the same JWT signing certificate baked into the installer. Buy the software, extract the key, mint admin tokens for any Device Sphere on the internet. CVE-2025-41672, CVSS 10.0. https://t.co/nlif3blCn1
Post summary
The text reveals that WAGO Device Sphere ships with a hard‑coded JWT signing certificate, enabling attackers to mint privileged admin tokens and potentially compromise any device, highlighting a high‑severity vulnerability (CVE-2025-41672) without providing a PoC or patch.
