PHOENIX CONTACT: OS Command Injection in WP 6xxx Web panels
Description
A remote low-privileged attacker can use a crafted HTTP POST request for certificate operations to gain full administrative access on Phoenix Contact WP 6xxx web panels before 4.0.10.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A remote low-privileged attacker can use a crafted HTTP POST request for certificate operations to gain full administrative access on Phoenix Contact WP 6xxx web panels before 4.0.10.
Vulnerability
In PHOENIX CONTACT WP 6xxx series web panels (versions prior to 4.0.10), a remote attacker with low privileges can exploit an issue in certificate operations via a crafted HTTP POST request. The vulnerability allows the attacker to escalate privileges and gain full device access. The affected product series includes WP 6001, WP 6002, WP 6012, WP 6032, WP 6042, WP 6082, WP 6122 and WP 6000 3G families [1].
Exploitation
The attacker must have low-privileged access (e.g., a standard user account) to the web panel's management interface. By sending a specifically crafted HTTP POST request related to certificate operations, the attacker can trigger the vulnerability. No further user interaction is required. The attack does not require any physical access or special network position beyond being able to reach the device's web interface [1].
Impact
Successful exploitation grants the attacker full access to the device, including the ability to execute commands as an administrative user (root), read arbitrary files, modify system configurations, and potentially compromise the confidentiality, integrity, and availability of the device. The attacker effectively obtains an administrative shell with full control [1].
Mitigation
Phoenix Contact has released firmware version 4.0.10 which fixes this vulnerability. Users should update their WP 6xxx devices to version 4.0.10 or later. If updating is not immediately possible, restrict network access to the web interface to trusted users and networks as a workaround. No other mitigations are documented in the available advisory [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
7- Range: <4.0.10
- PHOENIX CONTACT/WP 6070-WVPSv5Range: 0
- PHOENIX CONTACT/WP 6101-WXPSv5Range: 0
- PHOENIX CONTACT/WP 6121-WXPSv5Range: 0
- PHOENIX CONTACT/WP 6156-WHPSv5Range: 0
- PHOENIX CONTACT/WP 6185-WHPSv5Range: 0
- PHOENIX CONTACT/WP 6215-WHPSv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.