Junglewise Threat Intelligence

CVE-2026-63587: Weidmueller IE-SR-2TX-WL-4G SMS authentication bypass

CVE-2026-63587 · Severity: high · CVSS 8.6 · Published 2026-08-25

Executive brief

Weidmueller IE-SR-2TX-WL-4G security routers support SMS-based remote control of critical device functions. An attacker able to send SMS messages to the device can disable password protection for SMS commands by submitting 5 failed authentication attempts, then executing SMS commands without authorization. This allows an attacker to tamper with device configuration, leak information, or cause complete service outages.

Technical details

The vulnerability is an authentication bypass in the SMS control function caused by an insecure retry counter implementation. When the 'Enable Password Authorization' setting is active, the device requires a password for SMS commands but automatically disables password authorization after 5 consecutive failed password attempts. An unauthenticated remote attacker with SMS sending capability can trigger this bypass by deliberately submitting 5 or more invalid passwords; subsequent SMS commands are then executed without authentication. Commands are limited to availability and configuration functions, resulting in potential configuration tampering, information disclosure, and denial of service. Fixed firmware versions (V1.74 and later for IE-SR-2TX-WL-4G) are available.

Affected products

  • Weidmueller IE-SR-2TX-WL-4G Firmware 1.67 < V1.74

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: advisory: VDE-2026-083

References

Related threats