Junglewise Threat Intelligence

CVE-2026-89207: Siemens WTV676 and WTV776 denial of service via input validation

CVE-2026-89207 · Severity: high · CVSS 6.5 · Published 2026-09-22

Executive brief

Siemens WTV676 and WTV776 are industrial control devices used in energy infrastructure for remote monitoring and management. These devices contain an input validation vulnerability that allows an unauthenticated attacker to force the devices into protection mode, disabling remote web-based connectivity and potentially causing operational outages in energy systems.

Technical details

The vulnerability is an input validation flaw (CWE-1287) in the web interface of Siemens WTV676 and WTV776 devices. The affected devices do not properly validate input received from backend services, allowing an unauthenticated remote attacker to trigger denial of service conditions. Exploitation requires network access to the device but no authentication or user interaction. When exploited, the attack forces the device into protection mode, which disables remote connectivity functions including web-based access, effectively denying legitimate operators from remotely managing the device. Patches are available: WTV676-HB6035 should be updated to version 3.94 or later, and WTV776-HB6035 should be updated to version 4.17 or later.

Affected products

  • Siemens WTV676-HB6035 Web Interface <3.94
  • Siemens WTV776-HB6035 Web Interface <4.17

Timeline

  • 2026-09-22: disclosed: CISA republication of Siemens ProductCERT advisory SSA-823812
  • 2026-09-22: patched: Patches available: WTV676 v3.94 and WTV776 v4.17

References