Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2026-67596: Weak Encoding for Password in CSL Mobile Limited CSL 1010 M2M 3G WiFi Module

0
Medium
VulnerabilityCVE-2026-67596cvecve-2026-67596
Published: 07/30/2026 (07/30/2026, 14:59:37 UTC)
Source: CVE Database V5
Vendor/Project: CSL Mobile Limited
Product: CSL 1010 M2M 3G WiFi Module

Description

The CSL 1010 M2M 3G WiFi Module firmware up to version 2.2.1.4 uses a weak single-byte XOR cipher with a static key to encrypt the configuration backup file. This weak encoding allows unauthenticated attackers to easily decrypt the Router.cfg backup file and recover sensitive information such as web administration and telnet passwords, WPA/WPA2 pre-shared keys, PPPoE and 3G/APN credentials, and SIM identifiers including IMSI and IMEI. The vulnerability has a medium severity rating with a CVSS 4.0 base score of 6.9. No official patch or remediation guidance has been provided by the vendor as of the publication date.

CVSS v4.0

Score 6.9medium

Attack Vector
Local
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
None
Vuln. Availability
None
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/30/2026, 18:07:42 UTC

Technical Analysis

CVE-2026-67596 describes a vulnerability in the CSL 1010 M2M 3G WiFi Module firmware (up to version 2.2.1.4) where the configuration backup file is protected by a weak encryption scheme. Specifically, a single-byte XOR cipher with a static key is used, which can be trivially reversed by unauthenticated attackers. Exploiting this weakness allows attackers to decrypt the Router.cfg backup file and extract all stored secrets in plaintext, including administrative passwords, wireless keys, network credentials, and SIM identifiers. This exposure compromises device security and confidentiality of sensitive credentials. No vendor advisory or patch information is currently available.

Potential Impact

An attacker with access to the configuration backup file can recover all stored secrets in plaintext, including web administration and telnet passwords, WPA/WPA2 pre-shared keys, PPPoE and 3G/APN credentials, and SIM identifiers such as IMSI and IMEI. This can lead to unauthorized access to device management interfaces and network services, potentially compromising the device and connected networks. The vulnerability requires local access to the backup file but does not require authentication.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to configuration backup files and avoid storing or transmitting them insecurely. Monitor for vendor updates regarding patches or official mitigations.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
VulnCheck
Date Reserved
2026-07-29T21:07:39.201Z
Cvss Version
4.0
State
PUBLISHED
Remediation Level
null

Threat ID: 6a6b8fac9c2644c7f87317b4

Added to database: 07/30/2026, 17:53:48 UTC

Last enriched: 07/30/2026, 18:07:42 UTC

Last updated: 07/30/2026, 18:46:02 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses