VYPR
Unrated severityNVD Advisory· Published Aug 9, 2023· Updated Oct 8, 2024

PHOENIX CONTACT: Unauthorized read-access of root filesystem in WP 6xxx Web panels

CVE-2023-37855

Description

A low-privileged remote attacker can read arbitrary files on Phoenix Contact WP 6xxx web panels (prior to 4.0.10) via the embedded Qt browser.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A low-privileged remote attacker can read arbitrary files on Phoenix Contact WP 6xxx web panels (prior to 4.0.10) via the embedded Qt browser.

Vulnerability

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10, a vulnerability allows a remote attacker with low privileges to gain limited read-access to the device filesystem through the embedded Qt browser. The attacker can read files that are accessible to the 'browser' user [1].

Exploitation

An attacker with low-privileged access (e.g., a standard user account) on the device can exploit this issue by leveraging the embedded Qt browser's ability to access the filesystem. No user interaction beyond the attacker's own actions is required, and the attack can be carried out remotely over the network [1].

Impact

Successful exploitation grants the attacker the ability to read arbitrary files from the device filesystem, limited only by the permissions of the 'browser' user. This can lead to the disclosure of sensitive information, such as configuration files, credentials, or other data stored on the device [1].

Mitigation

The vulnerability is fixed in firmware version 4.0.10 of the WP 6xxx series. Users should upgrade to this version or later. No workarounds are available. The advisory from VDE provides further details [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

7
  • PHOENIX CONTACT/WP 6070-WVPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6101-WXPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6121-WXPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6156-WHPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6185-WHPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6215-WHPSv5
    Range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.