Weak Encryption Vulnerability in CSL 1010 M2M 3G WiFi Module by CSL
CVE-2026-67596

6.9MEDIUM

Key Information:

Vendor
CVE Published:
30 July 2026

What is CVE-2026-67596?

The firmware of the CSL 1010 M2M 3G WiFi Module, specifically versions up to 2.2.1.4, is susceptible to a weak encryption flaw. This vulnerability allows unauthenticated attackers to recover plaintext secrets from the device by exploiting a reverse engineering technique on a static key applied to configuration backup files. The Router.cfg backup file can be easily decrypted, revealing sensitive information such as web administration and Telnet passwords, WPA/WPA2 pre-shared keys, PPPoE and 3G/APN credentials, as well as crucial identifiers like IMSI and IMEI. This poses a significant risk to users and enhances the threat landscape associated with networked devices.

Affected Version(s)

CSL 1010 M2M 3G WiFi Module 0 <= 2.2.1.4

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gjoko Krstic of Zero Science Lab
.