VYPR
patchPublished Sep 22, 2026· 1 source

Siemens WTV676 and WTV776 Devices Vulnerable to Denial-of-Service Attack

Siemens WTV676 and WTV776 industrial devices are susceptible to a denial-of-service vulnerability, CVE-2026-89207, which can disable web access.

Siemens has issued a security advisory detailing a denial-of-service (DoS) vulnerability affecting its WTV676 and WTV776 industrial devices. The vulnerability, identified as CVE-2026-89207, stems from improper input validation within the devices' web interface.

An unauthenticated remote attacker can exploit this flaw by sending specially crafted input to the device. Successful exploitation could force the affected Siemens devices into a protection mode, which critically disables their web access functionality. This effectively cuts off remote management and monitoring capabilities, potentially leading to operational disruptions in critical infrastructure environments.

The specific affected versions include WTV676-HB6035 Web Interface versions prior to V3.94 and WTV776-HB6035 Web Interface versions prior to V4.17. The vulnerability carries a CVSS v3.1 base score of 6.5, classifying it as medium severity, but its impact on operational continuity can be significant.

Siemens has addressed this vulnerability by releasing updated firmware versions. Users are strongly recommended to update their WTV676 devices to V3.94 or later, and WTV776 devices to V4.17 or later. These updates are available through Siemens' support portal.

In addition to applying the vendor fix, Siemens advises implementing general security best practices. This includes protecting network access to affected products using appropriate security mechanisms and ensuring devices operate within a secure IT environment. Minimizing network exposure and isolating control system networks behind firewalls are also recommended.

CISA has also provided guidance, emphasizing the need to minimize network exposure for all control system devices and ensure they are not accessible from the internet. When remote access is necessary, secure methods like VPNs should be employed, with the caveat that VPNs themselves must be kept up-to-date.

The vulnerability was reported to CISA by Siemens ProductCERT, highlighting the collaborative effort in identifying and mitigating such threats within the industrial control systems (ICS) landscape. Organizations are encouraged to perform thorough impact and risk assessments before deploying any defensive measures.

This advisory serves as a reminder of the ongoing security challenges facing industrial environments, where the availability and integrity of control systems are paramount. Prompt patching and adherence to security best practices are crucial for maintaining operational resilience against potential cyber threats.

Synthesized by Vypr AI