CVE-2026-89207

LOWCVSS 6.9 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been identified in WTV676-HB6035 Web Interface (All versions < V3.94), WTV776-HB6035 Web Interface (All versions < V4.17). Affected devices do not properly validate input received from backend services. This could allow an unauthenticated remote attacker to force the device into protection mode, which results in losing remote connectivity functions (Web Access).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-09-22: 209-22
Referenced assets1 URL
Full discourse2 posts
  • Aviatrix Threat Research Center@aviatrixtrc

    TRC analysis shows attackers can force Siemens WTV676/WTV776 industrial control devices into protection mode through unauthenticated remote exploitation of CVE-2026-89207. The attack disables remote connectivity functions across critical energy infrastructure without requiring authentication. #CriticalInfrastructure 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/siemens-wtv676-wtv776-cve-2026-89207-denial-service-vulnerability

    0000043
    2.0K followersView on X
  • NewsTongue@NewsTongueX

    🔴 Siemens ICS devices vulnerable to denial-of-service attack disabling remote access Siemens WTV676 and WTV776 industrial control system devices contain an unauthenticated denial-of-service vulnerability (CVE-2026-89207) that allows remote attackers to force devices into protection mode, disabling web access and remote connectivity functions. • Affected versions: WTV676-HB6035 Web Interface < V3.94; WTV776-HB6035 Web Interface < V4.17 • Flaw: improper input validation from backend services • Deployed worldwide in energy critical infrastructure • Siemens released patches; users should update to V3.94 or V4.17 or later

    0000047
    901 followersView on X

Explore more