Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.3%top 81%

CVE-2026-63587: CWE-288 Authentication Bypass Using an Alternate Path or Channel in Weidmueller Interface IE-SR-2TX-WL-4G-EU

0
High
Published: 08/25/2026 (08/25/2026, 09:30:38 UTC)
Source: CVE Database V5
Vendor/Project: Weidmueller Interface
Product: IE-SR-2TX-WL-4G-EU

Description

The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliberately trigger this by submitting 5 or more invalid passwords, after which subsequent SMS commands are executed without requiring a password, resulting in potential limited configuration tampering, limited information leakage and potentially full loss of availability.

CVSS v4.0

Score 8.8high

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
Low
Vuln. Integrity
Low
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N

Affected software

GitHub Actionsmore threats →ai
weidmueller/interface-ie-sr-2tx-wl-4g-eu
pkg:github/weidmueller/interface-ie-sr-2tx-wl-4g-eu
Affected versions
=1.67

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/25/2026, 09:24:25 UTC

Technical Analysis

The IE-SR-2TX-WL-4G-EU device includes an SMS control function that can require password authorization for SMS commands. When the 'Enable Password Authorization' setting is active, the device increments a retry counter on each failed SMS password attempt. After 5 consecutive failed attempts, the device automatically disables SMS password authorization, allowing unauthenticated SMS commands to be executed. An unauthenticated remote attacker who can send SMS messages to the device can exploit this behavior to bypass authentication, potentially causing limited configuration changes, information leakage, or full loss of availability. This vulnerability is identified as CWE-288 and has a CVSS 4.0 score of 8.8 (high severity). The affected version is exactly 1.67. No patch or official remediation has been published as of the data provided.

Potential Impact

An unauthenticated remote attacker can bypass SMS password authentication by triggering the automatic disabling of password authorization after multiple failed attempts. This allows the attacker to send SMS commands without authentication, leading to limited configuration tampering, limited information leakage, and potentially full denial of service (loss of availability) on the affected device.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict SMS message access to the device from trusted sources only, if possible, to reduce exposure. Monitor device behavior for unauthorized SMS commands. No official patch or workaround has been published at this time.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
CERTVDE
Date Reserved
2026-07-17T06:47:50.712Z
Cvss Version
4.0
State
PUBLISHED
Remediation Level
null

Threat ID: 6a8d5b63acd9273b49f36566

Added to database: 08/25/2026, 09:07:47 UTC

Last enriched: 08/25/2026, 09:24:25 UTC

Last updated: 08/25/2026, 22:52:13 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses