VYPR
Unrated severityNVD Advisory· Published Aug 8, 2023· Updated Oct 15, 2024

PHOENIX CONTACT: OS Command Injection in WP 6xxx Web panels

CVE-2023-3572

Description

A remote, unauthenticated attacker can exploit a date/time POST request attribute to gain full administrative access on Phoenix Contact WP 6xxx series web panels prior to 4.0.10.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A remote, unauthenticated attacker can exploit a date/time POST request attribute to gain full administrative access on Phoenix Contact WP 6xxx series web panels prior to 4.0.10.

Vulnerability

In PHOENIX CONTACT WP 6xxx series web panels versions prior to 4.0.10, a remote, unauthenticated attacker can abuse a specific attribute of an HTTP POST request related to date/time operations. This vulnerability allows full device access without any prior authentication. The affected product line includes WP 6000, WP 6100, and WP 6200 series devices running firmware versions below 4.0.10 [1].

Exploitation

An attacker needs only network access to the web panel's management interface. No authentication or user interaction is required. The attacker crafts a specially designed HTTP POST request, incorporating a specific attribute tied to date/time functionality, which triggers the flaw. The request is sent to the device's web server, leading to unauthorized administrative access [1].

Impact

Successful exploitation grants the attacker full control over the affected device. This includes the ability to execute arbitrary OS commands with administrative privileges, read any files accessible to the 'browser' user, and compromise the confidentiality, integrity, and availability of the device. The attacker can gain an administrative shell and perform any action on the system [1].

Mitigation

PHOENIX CONTACT has released firmware version 4.0.10 to address this vulnerability. Users should update their devices to this version or later. No workaround is available for unpatched versions. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog as of the publication date [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

7
  • PHOENIX CONTACT/WP 6070-WVPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6101-WXPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6121-WXPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6156-WHPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6185-WHPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6215-WHPSv5
    Range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.