CVE-2026-67596: Weak Encoding for Password in CSL Mobile Limited CSL 1010 M2M 3G WiFi Module
CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticated attackers to recover all stored secrets in plaintext by reversing a single-byte XOR cipher that uses a static key to obfuscate the configuration backup file. Attackers can trivially decrypt the Router.cfg backup file to expose web administration and telnet passwords, WPA/WPA2 pre-shared keys, PPPoE and 3G/APN credentials, and SIM identifiers including IMSI and IMEI.
AI Analysis
Technical Summary
CVE-2026-67596 describes a vulnerability in the CSL 1010 M2M 3G WiFi Module firmware (up to version 2.2.1.4) where the configuration backup file is protected by a weak encryption scheme. Specifically, a single-byte XOR cipher with a static key is used, which can be trivially reversed by unauthenticated attackers. Exploiting this weakness allows attackers to decrypt the Router.cfg backup file and extract all stored secrets in plaintext, including administrative passwords, wireless keys, network credentials, and SIM identifiers. This exposure compromises device security and confidentiality of sensitive credentials. No vendor advisory or patch information is currently available.
Potential Impact
An attacker with access to the configuration backup file can recover all stored secrets in plaintext, including web administration and telnet passwords, WPA/WPA2 pre-shared keys, PPPoE and 3G/APN credentials, and SIM identifiers such as IMSI and IMEI. This can lead to unauthorized access to device management interfaces and network services, potentially compromising the device and connected networks. The vulnerability requires local access to the backup file but does not require authentication.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to configuration backup files and avoid storing or transmitting them insecurely. Monitor for vendor updates regarding patches or official mitigations.
CVE-2026-67596: Weak Encoding for Password in CSL Mobile Limited CSL 1010 M2M 3G WiFi Module
Description
CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticated attackers to recover all stored secrets in plaintext by reversing a single-byte XOR cipher that uses a static key to obfuscate the configuration backup file. Attackers can trivially decrypt the Router.cfg backup file to expose web administration and telnet passwords, WPA/WPA2 pre-shared keys, PPPoE and 3G/APN credentials, and SIM identifiers including IMSI and IMEI.
CVSS v4.0
Score 6.9medium
Affected software
CSL Mobile Limited
CSL 1010 M2M 3G WiFi Module
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-67596 describes a vulnerability in the CSL 1010 M2M 3G WiFi Module firmware (up to version 2.2.1.4) where the configuration backup file is protected by a weak encryption scheme. Specifically, a single-byte XOR cipher with a static key is used, which can be trivially reversed by unauthenticated attackers. Exploiting this weakness allows attackers to decrypt the Router.cfg backup file and extract all stored secrets in plaintext, including administrative passwords, wireless keys, network credentials, and SIM identifiers. This exposure compromises device security and confidentiality of sensitive credentials. No vendor advisory or patch information is currently available.
Potential Impact
An attacker with access to the configuration backup file can recover all stored secrets in plaintext, including web administration and telnet passwords, WPA/WPA2 pre-shared keys, PPPoE and 3G/APN credentials, and SIM identifiers such as IMSI and IMEI. This can lead to unauthorized access to device management interfaces and network services, potentially compromising the device and connected networks. The vulnerability requires local access to the backup file but does not require authentication.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to configuration backup files and avoid storing or transmitting them insecurely. Monitor for vendor updates regarding patches or official mitigations.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-29T21:07:39.201Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a6b8fac9c2644c7f87317b4
Added to database: 07/30/2026, 17:53:48 UTC
Last enriched: 07/30/2026, 18:07:42 UTC
Last updated: 09/12/2026, 22:01:36 UTC
Views: 83
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.