PHOENIX CONTACT: Unauthorized read-access of root filesystem in WP 6xxx Web panels
Description
A low-privileged remote attacker can read arbitrary files on Phoenix Contact WP 6xxx web panels (prior to 4.0.10) via the embedded Qt browser.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A low-privileged remote attacker can read arbitrary files on Phoenix Contact WP 6xxx web panels (prior to 4.0.10) via the embedded Qt browser.
Vulnerability
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10, a vulnerability allows a remote attacker with low privileges to gain limited read-access to the device filesystem through the embedded Qt browser. The attacker can read files that are accessible to the 'browser' user [1].
Exploitation
An attacker with low-privileged access (e.g., a standard user account) on the device can exploit this issue by leveraging the embedded Qt browser's ability to access the filesystem. No user interaction beyond the attacker's own actions is required, and the attack can be carried out remotely over the network [1].
Impact
Successful exploitation grants the attacker the ability to read arbitrary files from the device filesystem, limited only by the permissions of the 'browser' user. This can lead to the disclosure of sensitive information, such as configuration files, credentials, or other data stored on the device [1].
Mitigation
The vulnerability is fixed in firmware version 4.0.10 of the WP 6xxx series. Users should upgrade to this version or later. No workarounds are available. The advisory from VDE provides further details [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
7- Range: <4.0.10
- PHOENIX CONTACT/WP 6070-WVPSv5Range: 0
- PHOENIX CONTACT/WP 6101-WXPSv5Range: 0
- PHOENIX CONTACT/WP 6121-WXPSv5Range: 0
- PHOENIX CONTACT/WP 6156-WHPSv5Range: 0
- PHOENIX CONTACT/WP 6185-WHPSv5Range: 0
- PHOENIX CONTACT/WP 6215-WHPSv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.