IM
IronMonkey Threat Research
‹ Back to ICS Advisories

SSA-823812: Denial of Service Vulnerability in WTV676 and WTV776 devices

MEDIUM
CVSS 6.5
Date 2026-09-16T00:00:00+00:00
Source siemens-productcert
Published by Siemens ProductCERT

// Description

The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access) to the devices. Siemens has released new versions for the affected products and recommends to update to the latest versions.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-89207 6.5 medium
CVE-2026-89207. Affected devices do not properly validate input received from backend services. This could allow an unauthenticated remote attacker to force the device into protection mode, which results in losing remote connectivity functions (Web Access).

// Remediations (2)

Patch: Update to V4.17 or later version
Update to V4.17 or later version
Patch: Update to V3.94 or later version
Update to V3.94 or later version

// References