VYPR
Unrated severityNVD Advisory· Published Aug 9, 2023· Updated Oct 10, 2024

PHOENIX CONTACT: OS Command Injection in WP 6xxx Web panels

CVE-2023-37861

Description

An authenticated attacker can upload a specially crafted certificate to PHOENIX CONTACT WP 6xxx series web panels (before 4.0.10) via HTTP POST to execute arbitrary commands as root.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An authenticated attacker can upload a specially crafted certificate to PHOENIX CONTACT WP 6xxx series web panels (before 4.0.10) via HTTP POST to execute arbitrary commands as root.

Vulnerability

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10, an authenticated remote attacker can cause arbitrary code execution with root permissions by uploading a specially crafted certificate to the device via an HTTP POST request [1]. The vulnerability lies in the certificate handling functionality accessible to authenticated users.

Exploitation

An attacker needs valid authentication credentials for the web panel. The attacker sends a crafted HTTP POST request containing a maliciously formed certificate file to the device. The improper validation of the certificate data leads to command injection or other code execution within the root context [1].

Impact

Upon successful exploitation, the attacker can execute arbitrary operating system commands with root privileges, compromising the confidentiality, integrity, and availability of the device. This includes gaining an administrative shell, reading arbitrary files, and performing other privileged actions [1].

Mitigation

Phoenix Contact released version 4.0.10 to address this vulnerability. Users should update their WP 6xxx series web panels to version 4.0.10 or later [1]. No workarounds have been disclosed in the available references.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

7
  • PHOENIX CONTACT/WP 6070-WVPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6101-WXPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6121-WXPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6156-WHPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6185-WHPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6215-WHPSv5
    Range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.