Authentication Bypass Vulnerability in IE-SR-2TX-WL-4G Devices by VDE
CVE-2026-63587

8.8HIGH

What is CVE-2026-63587?

The SMS control feature of IE-SR-2TX-WL-4G devices can be exploited due to improper password authorization settings. When the 'Enable Password Authorization' feature is active, the device counts failed password attempts, disabling SMS password protection after five failed tries. An attacker can exploit this by sending multiple incorrect SMS commands, which leads to unauthorized SMS command execution without the need for a password. This vulnerability may allow attackers to tamper with configurations, access limited data, or disrupt the device's availability.

Affected Version(s)

IE-SR-2TX-WL-4G-EU 1.67 < 1.74

IE-SR-2TX-WL-4G-US-V 1.67 < 1.74

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.