CVE-2026-63587
Received Received - Intake

Unauthenticated SMS Command Execution in IE-SR-2TX-WL-4G

Vulnerability report for CVE-2026-63587, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-25

Assigner: CERT VDE

Description

The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliberately trigger this by submitting 5 or more invalid passwords, after which subsequent SMS commands are executed without requiring a password, resulting in potential limited configuration tampering, limited information leakage and potentially full loss of availability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-25
Generated
2026-08-25
AI Q&A
2026-08-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
weidmueller ie-sr-2tx-wl-4g *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-288 The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an authentication bypass vulnerability in Weidmueller IE-SR-2TX-WL-4G security routers. An unauthenticated remote attacker can send five or more invalid SMS passwords to disable the SMS password authorization feature. After this, all subsequent SMS commands are executed without requiring a password, allowing potential configuration changes, information access, or service disruption.

Detection Guidance

Monitor SMS traffic to the device for repeated failed password attempts. Check logs for 5 consecutive invalid SMS password attempts within a short timeframe. Inspect network traffic for unauthorized SMS command execution after such attempts.

Impact Analysis

An attacker could exploit this to modify device configurations, access sensitive information, or cause a loss of availability by disabling critical services. The impact includes limited tampering, data exposure, and potential full system downtime.

Compliance Impact

This vulnerability could lead to unauthorized configuration changes, information leakage, or loss of availability, which may violate compliance requirements for data protection and system integrity in standards like GDPR and HIPAA. Unauthorized access to device settings could result in improper handling of sensitive data or disruptions to critical services.

Mitigation Strategies

Disable SMS control message reception until firmware is updated. Restrict physical and network access to the device. Monitor for unusual SMS activity or unauthorized commands.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-63587. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart