Description
The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliberately trigger this by submitting 5 or more invalid passwords, after which subsequent SMS commands are executed without requiring a password, resulting in potential limited configuration tampering, limited information leakage and potentially full loss of availability.
Published: 2026-08-25
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The IE‑SR‑2TX‑WL‑4G devices use SMS as a control interface that can be protected by a password. The firmware increments a retry counter for each failed SMS password attempt; after five consecutive failures the password protection is automatically disabled, allowing any subsequent SMS command to be executed without authentication. An unauthenticated adversary can therefore craft five wrong passwords, trigger the counter, and then send arbitrary configuration or control messages. This can lead to limited configuration changes, data exposure, and potentially loss of device availability, all with no current authentication barrier.

Affected Systems

The vulnerability affects Weidmueller Interface products IE‑SR‑2TX‑WL‑4G‑EU and IE‑SR‑2TX‑WL‑4G‑US‑V. No specific firmware release is listed, so the issue may exist in all current releases of those models.

Risk and Exploitability

The flaw carries a CVSS score of 8.8, indicating high severity. EPSS data is not available, and the bug is not currently listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a remote attacker who can send SMS messages to the device; by intentionally sending five invalid passwords the attacker can disable the password requirement and then issue any SMS command without further authentication. The exploitation requires only the ability to transmit SMS to the device, making it a low‑entry‑barrier attack once the attacker knows the device number.

Generated by OpenCVE AI on August 25, 2026 at 10:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available firmware patch that removes the intruder‑triggered password bypass.
  • Reconfigure the device to disable SMS password authorization or turn off the SMS interface entirely until a patch is installed.
  • Limit SMS traffic to known, trusted senders or block the SMS gateway from untrusted networks to reduce the attacker’s ability to send the necessary SMS commands.

Generated by OpenCVE AI on August 25, 2026 at 10:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Description The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliberately trigger this by submitting 5 or more invalid passwords, after which subsequent SMS commands are executed without requiring a password, resulting in potential limited configuration tampering, limited information leakage and potentially full loss of availability.
Title SMS Password Authorization Bypass via Failed Attempt Counter
First Time appeared Weidmueller
Weidmueller fwr Ie Sr 2tx Wl 4g Eu Us
Weaknesses CWE-288
CPEs cpe:2.3:o:weidmueller:fwr_ie_sr_2tx_wl_4g_eu_us:*:*:*:*:*:*:*:*
Vendors & Products Weidmueller
Weidmueller fwr Ie Sr 2tx Wl 4g Eu Us
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Weidmueller Fwr Ie Sr 2tx Wl 4g Eu Us
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-08-25T08:55:12.442Z

Reserved: 2026-07-17T06:47:50.712Z

Link: CVE-2026-63587

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T09:17:32.057

Modified: 2026-08-25T09:17:32.057

Link: CVE-2026-63587

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T10:30:05Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel