VYPR
Unrated severityNVD Advisory· Published Aug 9, 2023· Updated Aug 2, 2024

PHOENIX CONTACT: Use of Hard-coded Credentials in WP 6xxx Web panels

CVE-2023-37858

Description

Hardcoded cryptographic keys in Phoenix Contact WP 6xxx web panels allow admin attackers to decrypt the web application login password.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Hardcoded cryptographic keys in Phoenix Contact WP 6xxx web panels allow admin attackers to decrypt the web application login password.

Vulnerability

In PHOENIX CONTACT WP 6xxx series web panels versions prior to 4.0.10, hardcoded cryptographic keys are stored in the device. These keys can be read by an authenticated attacker with admin privileges, enabling decryption of the encrypted web application login password [1].

Exploitation

An attacker must have network access to the device and valid administrative credentials. Once authenticated, the attacker can extract the hardcoded keys and use them to decrypt the stored encrypted password for the web service [1].

Impact

Successful exploitation allows the attacker to recover the plaintext web application login password, compromising confidentiality. With the password, the attacker can impersonate the legitimate web service user, potentially gaining further unauthorized access to device functions [1].

Mitigation

Phoenix Contact has released version 4.0.10 which removes the hardcoded cryptographic keys. Users should update to version 4.0.10 or later as soon as possible [1]. No workaround is available.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

7
  • PHOENIX CONTACT/WP 6070-WVPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6101-WXPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6121-WXPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6156-WHPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6185-WHPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6215-WHPSv5
    Range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.