CVE-2026-89207: Medium severity vulnerability
A vulnerability has been identified in WTV676-HB6035 Web Interface (All versions < V3.94), WTV776-HB6035 Web Interface (All versions < V4.17). Affected devices do not properly validate input received from backend services. This could allow an unauthenticated remote attacker to force the device into protection mode, which results in losing remote connectivity functions (Web Access).
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WTV676-HB6035 Web Interfaceto a version that resolves this vulnerability.Fixed in V3.94 - Upgrade
Upgrade
WTV776-HB6035 Web Interfaceto a version that resolves this vulnerability.Fixed in V4.17 - Compensating control
To maintain remote access while the issue is being remediated, use an alternative connectivity path for Web Access (e.g., local access or another supported remote method) since forced protection mode can result in losing remote connectivity functions.
Event History
Frequently Asked Questions
Which device versions are affected?
WTV676-HB6035 Web Interface versions earlier than V3.94 and WTV776-HB6035 Web Interface versions earlier than V4.17 are affected.
Does exploitation require authentication or user interaction?
No. The vulnerability can be exploited by an unauthenticated remote attacker and does not require user interaction.
What is the practical impact of a successful attack?
An attacker can force the affected device into protection mode. This causes loss of remote connectivity functions, including Web Access.