PT-2026-66507 · Unknown · Csl 1010 M2M 3G Wifi Module
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
CSL 1010 M2M 3G WiFi Module versions prior to 2.2.1.5
Description
The firmware uses a weak single-byte XOR cipher with a static key to obfuscate the configuration backup file. This allows unauthenticated attackers to reverse the cipher and recover stored secrets in plaintext from the
Router.cfg backup file. Exposed information includes web administration and telnet passwords, WPA/WPA2 pre-shared keys, PPPoE and 3G/APN credentials, and SIM identifiers such as IMSI and IMEI.Recommendations
Update CSL 1010 M2M 3G WiFi Module to a version newer than 2.2.1.4.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Csl 1010 M2M 3G Wifi Module