PHOENIX CONTACT: Command Injection in WP 6xxx Web panels
CVE-2023-3573
8.8HIGH
What is CVE-2023-3573?
A command injection vulnerability exists in PHOENIX CONTACT's WP 6xxx series web panels in versions prior to 4.0.10. This issue allows a remote attacker with low privileges to exploit the vulnerability through a crafted HTTP POST request related to font configuration operations. Once successfully exploited, the attacker may gain full control over the device, posing significant risks to security and data integrity.
Affected Version(s)
WP 6070-WVPS 0 < 4.0.10
WP 6101-WXPS 0 < 4.0.10
WP 6121-WXPS 0 < 4.0.10