Junglewise Threat Intelligence

CVE-2026-67596: CSL 1010 M2M 3G WiFi Module weak encryption in Router.cfg

CVE-2026-67596 · Severity: medium · CVSS 6.2 · Published 2026-07-30

Executive brief

The CSL 1010 M2M 3G WiFi Module, a device used for machine-to-machine wireless connectivity, contains a security flaw in how it protects its configuration backups. An attacker who gains access to the device's backup file can easily bypass the encryption to view sensitive information in plain text. This includes administrative passwords, WiFi keys, and cellular credentials, which could lead to unauthorized network access or complete takeover of the device.

Technical details

The CSL 1010 M2M 3G WiFi Module firmware (up to version 2.2.1.4) implements a weak encryption scheme for its 'Router.cfg' configuration backup file. The device uses a single-byte XOR cipher with a static, hardcoded key to obfuscate sensitive data. An attacker with access to the backup file can trivially reverse this operation to recover plaintext secrets, including web administration and telnet passwords, WPA/WPA2 pre-shared keys, PPPoE and 3G/APN credentials, and SIM identifiers (IMSI/IMEI). While the CVSS vector indicates local access (AV:L), this typically refers to the requirement of obtaining the configuration file from the device or its management environment.

Affected products

  • CSL Mobile Limited 1010 M2M 3G WiFi Module through 2.2.1.4

Timeline

  • 2026-07-30: advisory: Initial disclosure by VulnCheck and Zero Science Lab

References