Description
A vulnerability has been identified in WTV676-HB6035 Web Interface (All versions < V3.94), WTV776-HB6035 Web Interface (All versions < V4.17). Affected devices do not properly validate input received from backend services.
This could allow an unauthenticated remote attacker to force the device into protection mode, which results in losing remote connectivity functions (Web Access).
Published: 2026-09-16
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service – Remote Web Access Disruption
Action: Apply Vendor Update
AI Analysis

Impact

An identified weakness in Siemens\" WTV676-HB6035 and WTV776-HB6035 Web Interfaces allows an attacker without credentials to exploit improper input handling from backend services. By sending crafted input, an attacker can force the device into protection mode, which terminates its remote connectivity features, specifically disabling web access. This results in a denial of web‑based management functionality and does not, as currently described, provide access to sensitive data or system control beyond service disruption.

Affected Systems

The flaw is present in all versions of the WTV676-HB6035 Web Interface earlier than V3.94 and in all versions of the WTV776-HB6035 Web Interface before V4.17. Siemens customers using these older firmware releases are impacted.

Risk and Exploitability

The CVSS base score of 6.9 indicates moderate severity, and the EPSS score below 1% suggests exploitation is unlikely but possible. Because the attack does not require authentication and can be performed remotely through the interface that communicates with backend services, the attack surface is relatively open, although the vulnerability is not listed in the CISA KEV catalog. The primary risk is loss of remote management capability rather than data compromise.

Generated by OpenCVE AI on September 18, 2026 at 12:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest firmware or patch released by Siemens for the WTV676-HB6035 and WTV776-HB6035 Web Interfaces
  • Restrict network access to the backend services that provide input to the Web Interface, using firewalls or VLAN segmentation to limit potential exploitation
  • Monitor device logs for unexpected transitions into protection mode and enforce alerts when such state changes occur

Generated by OpenCVE AI on September 18, 2026 at 12:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Remote Attacker Can Force Device into Protection Mode Disabling Web Access

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens wtv676-hb6035 Web Interface
Siemens wtv776-hb6035 Web Interface
Vendors & Products Siemens
Siemens wtv676-hb6035 Web Interface
Siemens wtv776-hb6035 Web Interface

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Remote Attacker Can Force Device into Protection Mode Disabling Web Access

Wed, 16 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in WTV676-HB6035 Web Interface (All versions < V3.94), WTV776-HB6035 Web Interface (All versions < V4.17). Affected devices do not properly validate input received from backend services. This could allow an unauthenticated remote attacker to force the device into protection mode, which results in losing remote connectivity functions (Web Access).
Weaknesses CWE-1287
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Siemens Wtv676-hb6035 Web Interface Wtv776-hb6035 Web Interface
cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2026-09-16T18:13:23.189Z

Reserved: 2026-09-11T07:45:20.919Z

Link: CVE-2026-89207

cve-icon Vulnrichment

Updated: 2026-09-16T18:13:17.121Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T08:16:40.440

Modified: 2026-09-18T19:25:59.470

Link: CVE-2026-89207

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T12:45:08Z

Weaknesses
  • CWE-1287

    Improper Validation of Specified Type of Input