CVE-2026-63587
Last modified
CVE-2026-63587 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliberately trigger this by submitting 5 or more invalid passwords, after which subsequent SMS commands are executed without requiring a password, resulting in potential limited configuration tampering, limited information leakage and potentially full loss of availability.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Weidmueller Interface | IE-SR-2TX-WL-4G-EU | >= 1.67, < 1.74 |
| Weidmueller Interface | IE-SR-2TX-WL-4G-US-V | >= 1.67, < 1.74 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-63587?
How severe is CVE-2026-63587?
How do I fix CVE-2026-63587?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-63559An integer overflow in the UA_Variant arrayDimensions produc…7.5
- CVE-2026-6356A vulnerability in the web application allows standard users…9.6
- CVE-2026-63563Sharp and Toshiba Tec MFPs (multifunction printers) for a ce…6.9
- CVE-2026-6357pip prior to version 26.1 would run self-update check functi…5.3
- CVE-2026-6358Use after free in XR in Google Chrome on Android prior to 14…8.8
- CVE-2026-63586The web-based management interface uses a modified uhttpd se…9.8
- CVE-2026-6359Use after free in Video in Google Chrome on Windows prior to…8.8
- CVE-2026-6360Use after free in FileSystem in Google Chrome prior to 147.0…8.8
- CVE-2026-6361Heap buffer overflow in PDFium in Google Chrome on Windows p…8.3
- CVE-2026-6362Use after free in Codecs in Google Chrome prior to 147.0.772…4.3
- CVE-2026-63621Improper Input Validation, Improper Neutralization of Specia…5.3
- CVE-2026-63622A flaw was found in libvirt. A local attacker, specifically …7.8
Are you affected by CVE-2026-63587?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
