CVE-2023-37861: Phoenixcontact Wp 6070-Wvps Firmware

High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated remote attacker can execute code with root permissions with a specially crafted HTTP POST when uploading a certificate to the device.

Affected products

Published 2023-08-09. Last modified 2026-06-17.