PHOENIX CONTACT: OS Command Injection in WP 6xxx Web panels
Description
A remote attacker with SNMPv2 write privileges can exploit a vulnerability in Phoenix Contact WP 6xxx web panels prior to 4.0.10 to gain full device access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A remote attacker with SNMPv2 write privileges can exploit a vulnerability in Phoenix Contact WP 6xxx web panels prior to 4.0.10 to gain full device access.
Vulnerability
In PHOENIX CONTACT's WP 6xxx series web panels in versions prior to 4.0.10, a vulnerability exists in the SNMP service that allows a remote attacker with SNMPv2 write privileges to send a specially crafted SNMP request to gain full administrative access to the device [1].
Exploitation
An attacker must have SNMPv2 write privileges to the affected device. By sending a specially crafted SNMP request, the attacker can trigger the vulnerability without requiring any additional authentication or user interaction [1].
Impact
Successful exploitation grants the attacker full administrative access to the device, including the ability to execute arbitrary OS commands, read arbitrary files, craft valid session cookies, decrypt the web service password, retrieve SNMP communities, and craft malicious firmware update packets [1].
Mitigation
Phoenix Contact has released firmware version 4.0.10 for the WP 6xxx series web panels to address this vulnerability. Users should update to this version or later as soon as possible [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
7- Range: <4.0.10
- PHOENIX CONTACT/WP 6070-WVPSv5Range: 0
- PHOENIX CONTACT/WP 6101-WXPSv5Range: 0
- PHOENIX CONTACT/WP 6121-WXPSv5Range: 0
- PHOENIX CONTACT/WP 6156-WHPSv5Range: 0
- PHOENIX CONTACT/WP 6185-WHPSv5Range: 0
- PHOENIX CONTACT/WP 6215-WHPSv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.