{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/wtv776-all-versions--4.17/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":6.5,"id":"CVE-2026-89207"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WTV676 (all versions \u003c 3.94)","WTV776 (all versions \u003c 4.17)"],"_cs_severities":["medium"],"_cs_tags":["industrial-control-systems","denial-of-service","energy"],"_cs_type":"advisory","_cs_vendors":["Siemens"],"content_html":"\u003cp\u003eSiemens WTV676 and WTV776 industrial communication devices are affected by a medium-severity vulnerability (CVE-2026-89207) stemming from improper validation of input received from backend services. An unauthenticated remote attacker can exploit this flaw to force the affected hardware into a protection mode. Once in this state, the devices disable their Web Access functionality, effectively resulting in a denial-of-service condition for remote management and connectivity. This vulnerability impacts devices deployed globally within the energy sector. Siemens has released patched firmware versions, and organizations are advised to update affected hardware and restrict network exposure for these devices.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a denial-of-service condition where remote administrative access via the Web Interface is disabled. This loss of connectivity may disrupt operational monitoring and management of systems within energy sector environments. The vulnerability is considered reachable by an unauthenticated attacker over the network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade WTV676 devices to firmware version 3.94 or later to address CVE-2026-89207.\u003c/li\u003e\n\u003cli\u003eUpgrade WTV776 devices to firmware version 4.17 or later to address CVE-2026-89207.\u003c/li\u003e\n\u003cli\u003eImplement network segmentation to isolate control system networks from the public internet and business networks.\u003c/li\u003e\n\u003cli\u003eEnforce strict access control lists (ACLs) to ensure that only authorized hosts can communicate with the device web interfaces.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-22T16:46:59Z","date_published":"2026-09-22T16:46:59Z","id":"https://feed.craftedsignal.io/briefs/2026-09-siemens-wtv-dos/","summary":"An unauthenticated remote attacker can exploit an improper input validation vulnerability (CVE-2026-89207) in Siemens WTV676 and WTV776 devices to force them into protection mode, resulting in a permanent loss of remote web access.","title":"Denial of Service Vulnerability in Siemens WTV676 and WTV776","url":"https://feed.craftedsignal.io/briefs/2026-09-siemens-wtv-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - WTV776 (All Versions \u003c 4.17)","version":"https://jsonfeed.org/version/1.1"}