Denial of Service Vulnerability in Siemens WTV676 and WTV776
An unauthenticated remote attacker can exploit an improper input validation vulnerability (CVE-2026-89207) in Siemens WTV676 and WTV776 devices to force them into protection mode, resulting in a permanent loss of remote web access.
CVE search metadata
CVE search record: CVE-2026-89207. Severity: medium. CVSS: 6.5. EPSS: 0.34%. KEV: no. Product: WTV676 (all versions < 3.94), WTV776 (all versions < 4.17). Brief: Denial of Service Vulnerability in Siemens WTV676 and WTV776. Brief link: https://feed.craftedsignal.io/briefs/2026-09-siemens-wtv-dos/
Siemens WTV676 and WTV776 industrial communication devices are affected by a medium-severity vulnerability (CVE-2026-89207) stemming from improper validation of input received from backend services. An unauthenticated remote attacker can exploit this flaw to force the affected hardware into a protection mode. Once in this state, the devices disable their Web Access functionality, effectively resulting in a denial-of-service condition for remote management and connectivity. This vulnerability impacts devices deployed globally within the energy sector. Siemens has released patched firmware versions, and organizations are advised to update affected hardware and restrict network exposure for these devices.
Impact
Successful exploitation results in a denial-of-service condition where remote administrative access via the Web Interface is disabled. This loss of connectivity may disrupt operational monitoring and management of systems within energy sector environments. The vulnerability is considered reachable by an unauthenticated attacker over the network.
Recommendation
- Upgrade WTV676 devices to firmware version 3.94 or later to address CVE-2026-89207.
- Upgrade WTV776 devices to firmware version 4.17 or later to address CVE-2026-89207.
- Implement network segmentation to isolate control system networks from the public internet and business networks.
- Enforce strict access control lists (ACLs) to ensure that only authorized hosts can communicate with the device web interfaces.
Immediate actions
Upgrade WTV676 devices to v3.94 and WTV776 devices to v4.17
Mitigations
Isolate affected devices from the internet using firewalls
CVE-2026-89207