PT-2026-81227 · Unknown · Ie-Sr-2Tx-Wl-4G

CVE-2026-63587

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions IE-SR-2TX-WL-4G (affected versions not specified)
Description The SMS control function allows for password protection of SMS commands through the 'Enable Password Authorization' setting. However, the device implements a retry counter that automatically disables password authorization after 5 consecutive failed attempts. An unauthenticated remote attacker can exploit this by sending 5 or more invalid passwords via SMS, allowing subsequent commands to be executed without authentication. This can lead to limited configuration tampering, limited information leakage, and a potential full loss of availability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63587

Affected Products

Ie-Sr-2Tx-Wl-4G