Siemens WTV676 and WTV776

Summary

Siemens WTV676 and WTV776 devices have a denial-of-service vulnerability (CVE-2026-89207) that can disable remote web access if exploited. An unauthenticated remote attacker could trigger this by forcing the device into protection mode. Siemens has released updated versions to address this issue.

IFF Assessment

FOE

This vulnerability allows an attacker to disable remote connectivity, impacting operational control and potentially leading to further disruptions.

Severity

6.5 Medium

Defender Context

This vulnerability impacts critical infrastructure sectors, specifically energy, highlighting the ongoing risks to industrial control systems. Defenders should prioritize patching or applying mitigations for affected Siemens devices to prevent denial-of-service attacks that could disrupt operations and remote management.

Read Full Story →