Weak Encryption Vulnerability in CSL 1010 M2M 3G WiFi Module by CSL
CVE-2026-67596
6.9MEDIUM
What is CVE-2026-67596?
The firmware of the CSL 1010 M2M 3G WiFi Module, specifically versions up to 2.2.1.4, is susceptible to a weak encryption flaw. This vulnerability allows unauthenticated attackers to recover plaintext secrets from the device by exploiting a reverse engineering technique on a static key applied to configuration backup files. The Router.cfg backup file can be easily decrypted, revealing sensitive information such as web administration and Telnet passwords, WPA/WPA2 pre-shared keys, PPPoE and 3G/APN credentials, as well as crucial identifiers like IMSI and IMEI. This poses a significant risk to users and enhances the threat landscape associated with networked devices.
Affected Version(s)
CSL 1010 M2M 3G WiFi Module 0 <= 2.2.1.4
