CVE-2026-63587 HIGH

CVE-2026-63587: SMS Password Authorization Bypass via Failed Attempt Counter

Vendor Weidmueller Interface
Product IE-SR-2TX-WL-4G-EU
Weakness CWE-288
Published August 25, 2026
Last update August 27, 2026

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliberately trigger this by submitting 5 or more invalid passwords, after which subsequent SMS commands are executed without requiring a password, resulting in potential limited configuration tampering, limited information leakage and potentially full loss of availability.

Key dates

02Disclosure timeline

August 25, 2026 CVE published
August 27, 2026 Record updated

Related vulnerabilities

04Related CVE