VYPR
Unrated severityNVD Advisory· Published Aug 9, 2023· Updated Oct 10, 2024

PHOENIX CONTACT: WP 6xxx Web panels prone to download code without integrity check

CVE-2023-37864

Description

A remote attacker with SNMPv2 write privileges can exploit a vulnerability in Phoenix Contact WP 6xxx web panels prior to 4.0.10 to gain full device access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A remote attacker with SNMPv2 write privileges can exploit a vulnerability in Phoenix Contact WP 6xxx web panels prior to 4.0.10 to gain full device access.

Vulnerability

In PHOENIX CONTACT WP 6xxx series web panels running versions prior to 4.0.10, a vulnerability exists in the handling of SNMPv2 requests. An attacker with SNMPv2 write privileges can send a specially crafted SNMP request that triggers a command injection or authentication bypass, leading to full device compromise. The affected product line includes all WP 6xxx models before firmware version 4.0.10 [1].

Exploitation

To exploit this vulnerability, an attacker must have SNMPv2 write access to the target device, which typically requires knowledge of the SNMP community string. The attacker sends a malicious SNMP request that exploits the flaw, potentially allowing arbitrary command execution or privilege escalation without further authentication. No user interaction is required, and the attack can be performed remotely over the network [1].

Impact

Successful exploitation grants the attacker full administrative access to the device. This includes the ability to execute arbitrary OS commands with administrative privileges, read any files accessible to the 'browser' user, craft valid session cookies, decrypt the web service password, retrieve SNMP communities, and craft malicious firmware update packets. The confidentiality, integrity, and availability of the device are completely compromised [1].

Mitigation

Phoenix Contact has released firmware version 4.0.10 to address this vulnerability. Users should update their WP 6xxx series web panels to version 4.0.10 or later. If immediate patching is not possible, restrict SNMPv2 write access to trusted hosts only and ensure SNMP community strings are strong and not shared. No workaround is available that fully mitigates the issue without upgrading [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

7
  • PHOENIX CONTACT/WP 6070-WVPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6101-WXPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6121-WXPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6156-WHPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6185-WHPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6215-WHPSv5
    Range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.