PHOENIX CONTACT: Use of Hard-coded Credentials in WP 6xxx Web panels
Description
Hardcoded cryptographic keys in Phoenix Contact WP 6xxx web panels allow admin attackers to decrypt the web application login password.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Hardcoded cryptographic keys in Phoenix Contact WP 6xxx web panels allow admin attackers to decrypt the web application login password.
Vulnerability
In PHOENIX CONTACT WP 6xxx series web panels versions prior to 4.0.10, hardcoded cryptographic keys are stored in the device. These keys can be read by an authenticated attacker with admin privileges, enabling decryption of the encrypted web application login password [1].
Exploitation
An attacker must have network access to the device and valid administrative credentials. Once authenticated, the attacker can extract the hardcoded keys and use them to decrypt the stored encrypted password for the web service [1].
Impact
Successful exploitation allows the attacker to recover the plaintext web application login password, compromising confidentiality. With the password, the attacker can impersonate the legitimate web service user, potentially gaining further unauthorized access to device functions [1].
Mitigation
Phoenix Contact has released version 4.0.10 which removes the hardcoded cryptographic keys. Users should update to version 4.0.10 or later as soon as possible [1]. No workaround is available.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
7- Range: <4.0.10
- PHOENIX CONTACT/WP 6070-WVPSv5Range: 0
- PHOENIX CONTACT/WP 6101-WXPSv5Range: 0
- PHOENIX CONTACT/WP 6121-WXPSv5Range: 0
- PHOENIX CONTACT/WP 6156-WHPSv5Range: 0
- PHOENIX CONTACT/WP 6185-WHPSv5Range: 0
- PHOENIX CONTACT/WP 6215-WHPSv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
0No linked articles in our index yet.