Executive brief
Weidmueller security routers (IE-SR-2TX-WL and IE-SR-2TX-WL-4G) used to manage industrial networks are vulnerable to unauthenticated remote code execution through their web-based management interface. An attacker with network access can execute arbitrary commands as root by injecting shell metacharacters into the login form, potentially compromising the entire router, intercepting network traffic, and disrupting critical operations.
Technical details
The vulnerability is an OS command injection (CWE-78) in the HTTP Basic Authentication handler of a custom uhttpd web server. The username from the Authorization header is passed unsanitized directly into a shell command executed via system(). An unauthenticated remote attacker can submit a specially crafted username containing shell metacharacters (e.g., backticks, pipes, semicolons) to break out of the intended command context and execute arbitrary shell commands with root privileges. No authentication or user interaction is required; the attack is network-accessible. Weidmueller has released patched firmware versions (V1.57+ for IE-SR-2TX-WL, V1.74+ for IE-SR-2TX-WL-4G).
Affected products
- Weidmueller IE-SR-2TX-WL Firmware < V1.57
- Weidmueller IE-SR-2TX-WL-4G Firmware < V1.74
Timeline
- 2026-08-25: disclosed: VDE-2026-083 and CVE-2026-63586 published
- 2026-08-25: patched: Firmware updates available: V1.57+ for IE-SR-2TX-WL, V1.74+ for IE-SR-2TX-WL-4G