Security/ siemens · ics · denial-of-service · energy-sector

Siemens Fixes Denial of Service Flaw in WTV676 and WTV776

An unauthenticated attacker could force Siemens WTV676 and WTV776 grid terminals into protection mode, cutting remote web access until patched.

Siemens has patched a flaw that can force two of its industrial web gateways offline with nothing more than bad input.

The vulnerability, tracked as CVE-2026-89207, sits in the web interface of the WTV676-HB6035 and WTV776-HB6035, below firmware versions 3.94 and 4.17 respectively. The devices don't properly validate input coming from backend services, and an unauthenticated attacker with network access can abuse that to trip the device into protection mode. That mode disables remote Web Access, the interface operators use to check in on the units without a site visit. Siemens scores the bug 6.5 out of 10 and has released fixed firmware for both product lines.

Both devices ship into energy-sector deployments worldwide, and protection mode is a blunt instrument: it doesn't leak data or hand over control, it just cuts remote visibility. For utilities that lean on remote monitoring specifically to avoid sending someone to a substation, an easy-to-trigger lockout is a real operational headache even without a flashy breach.

It's an availability bug, not a takeover - more a self-inflicted blackout of the dashboard than a burglar in the system, but the fix is a firmware update away, so there's no excuse to sit on it.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →