Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-63587— SMS Password Authorization Bypass via Failed Attempt Counter

Quick assessment

Affected
Weidmueller Interface IE-SR-2TX-WL-4G-EU
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

IE-SR-2TX-WL-4G 设备的短信控制功能可通过“启用密码认证”(Enable Password Authorization)设置,要求对短信命令进行密码验证。每次短信密码验证失败时,设备会递增重试计数器;在连续5次密码验证失败后,系统将自动禁用短信密码认证功能。攻击者若能向该设备发送短信(无需身份认证),可通过故意提交5次或以上的错误密码来触发此机制。此后,后续的短信命令将在无需密码验证的情况下被执行,从而导致潜在的有限配置篡改、有限的信息泄露,以及可能的完全可用性丧失(拒绝服务)。

CVSS 8.6 · High EPSS 0.27% · P19

Affected Version Matrix 2

VendorProduct Version RangeStatus
Weidmueller Interface IE-SR-2TX-WL-4G-EU 1.67< 1.74 affected
Weidmueller Interface IE-SR-2TX-WL-4G-US-V 1.67< 1.74 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-63587

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SMS Password Authorization Bypass via Failed Attempt Counter
Source: CVE Program / CVE List V5
Vulnerability Description
The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliberately trigger this by submitting 5 or more invalid passwords, after which subsequent SMS commands are executed without requiring a password, resulting in potential limited configuration tampering, limited information leakage and potentially full loss of availability.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
使用候选路径或通道进行的认证绕过
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Weidmueller Interface IE-SR-2TX-WL-4G-EU 1.67 ~ 1.74 -
Weidmueller Interface IE-SR-2TX-WL-4G-US-V 1.67 ~ 1.74 -

II. Public POCs for CVE-2026-63587

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-63587

登录查看更多情报信息。

Vendor Advisories for CVE-2026-63587 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-63587

No comments yet


Leave a comment