PHOENIX CONTACT: Missing Authorization in WP 6xxx Web panels
Description
Unauthenticated remote attacker can access upload functions of HTTP API in WP 6xxx web panels prior to 4.0.10, triggering certificate errors and partial denial-of-service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Unauthenticated remote attacker can access upload functions of HTTP API in WP 6xxx web panels prior to 4.0.10, triggering certificate errors and partial denial-of-service.
Vulnerability
In PHOENIX CONTACT's WP 6xxx series web panels, versions prior to 4.0.10, an unauthenticated remote attacker can access upload functions of the HTTP API. This vulnerability exists due to missing authentication on those endpoints. The affected products include various WP 6xxx models [1].
Exploitation
The attacker does not require any authentication or prior access. By sending crafted HTTP requests to the upload functions, the attacker can trigger certificate errors for SSL connections. The exact steps involve accessing the upload API endpoints without credentials [1].
Impact
Successful exploitation may cause certificate errors for SSL connections, leading to a partial denial-of-service. The confidentiality and integrity of communications may be compromised due to degraded TLS security. The attacker does not gain code execution or data access directly from this vulnerability [1].
Mitigation
The vulnerability is fixed in version 4.0.10 of the WP 6xxx firmware. Users should update to this version or later. There are no reported workarounds; however, restricting network access to the web panel can reduce exposure [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
7- Range: <4.0.10
- PHOENIX CONTACT/WP 6070-WVPSv5Range: 0
- PHOENIX CONTACT/WP 6101-WXPSv5Range: 0
- PHOENIX CONTACT/WP 6121-WXPSv5Range: 0
- PHOENIX CONTACT/WP 6156-WHPSv5Range: 0
- PHOENIX CONTACT/WP 6185-WHPSv5Range: 0
- PHOENIX CONTACT/WP 6215-WHPSv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.