VYPR
Unrated severityNVD Advisory· Published Aug 8, 2023· Updated Nov 4, 2024

PHOENIX CONTACT: OS Command Injection in WP 6xxx Web panels

CVE-2023-3571

Description

A remote low-privileged attacker can use a crafted HTTP POST request for certificate operations to gain full administrative access on Phoenix Contact WP 6xxx web panels before 4.0.10.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A remote low-privileged attacker can use a crafted HTTP POST request for certificate operations to gain full administrative access on Phoenix Contact WP 6xxx web panels before 4.0.10.

Vulnerability

In PHOENIX CONTACT WP 6xxx series web panels (versions prior to 4.0.10), a remote attacker with low privileges can exploit an issue in certificate operations via a crafted HTTP POST request. The vulnerability allows the attacker to escalate privileges and gain full device access. The affected product series includes WP 6001, WP 6002, WP 6012, WP 6032, WP 6042, WP 6082, WP 6122 and WP 6000 3G families [1].

Exploitation

The attacker must have low-privileged access (e.g., a standard user account) to the web panel's management interface. By sending a specifically crafted HTTP POST request related to certificate operations, the attacker can trigger the vulnerability. No further user interaction is required. The attack does not require any physical access or special network position beyond being able to reach the device's web interface [1].

Impact

Successful exploitation grants the attacker full access to the device, including the ability to execute commands as an administrative user (root), read arbitrary files, modify system configurations, and potentially compromise the confidentiality, integrity, and availability of the device. The attacker effectively obtains an administrative shell with full control [1].

Mitigation

Phoenix Contact has released firmware version 4.0.10 which fixes this vulnerability. Users should update their WP 6xxx devices to version 4.0.10 or later. If updating is not immediately possible, restrict network access to the web interface to trusted users and networks as a workaround. No other mitigations are documented in the available advisory [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

7
  • PHOENIX CONTACT/WP 6070-WVPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6101-WXPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6121-WXPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6156-WHPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6185-WHPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6215-WHPSv5
    Range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.