PHOENIX CONTACT: OS Command Injection in WP 6xxx Web panels
Description
An authenticated attacker can upload a specially crafted certificate to PHOENIX CONTACT WP 6xxx series web panels (before 4.0.10) via HTTP POST to execute arbitrary commands as root.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An authenticated attacker can upload a specially crafted certificate to PHOENIX CONTACT WP 6xxx series web panels (before 4.0.10) via HTTP POST to execute arbitrary commands as root.
Vulnerability
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10, an authenticated remote attacker can cause arbitrary code execution with root permissions by uploading a specially crafted certificate to the device via an HTTP POST request [1]. The vulnerability lies in the certificate handling functionality accessible to authenticated users.
Exploitation
An attacker needs valid authentication credentials for the web panel. The attacker sends a crafted HTTP POST request containing a maliciously formed certificate file to the device. The improper validation of the certificate data leads to command injection or other code execution within the root context [1].
Impact
Upon successful exploitation, the attacker can execute arbitrary operating system commands with root privileges, compromising the confidentiality, integrity, and availability of the device. This includes gaining an administrative shell, reading arbitrary files, and performing other privileged actions [1].
Mitigation
Phoenix Contact released version 4.0.10 to address this vulnerability. Users should update their WP 6xxx series web panels to version 4.0.10 or later [1]. No workarounds have been disclosed in the available references.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
7- Range: <4.0.10
- PHOENIX CONTACT/WP 6070-WVPSv5Range: 0
- PHOENIX CONTACT/WP 6101-WXPSv5Range: 0
- PHOENIX CONTACT/WP 6121-WXPSv5Range: 0
- PHOENIX CONTACT/WP 6156-WHPSv5Range: 0
- PHOENIX CONTACT/WP 6185-WHPSv5Range: 0
- PHOENIX CONTACT/WP 6215-WHPSv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.