Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-083/ |
|
Tue, 25 Aug 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliberately trigger this by submitting 5 or more invalid passwords, after which subsequent SMS commands are executed without requiring a password, resulting in potential limited configuration tampering, limited information leakage and potentially full loss of availability. | |
| Title | SMS Password Authorization Bypass via Failed Attempt Counter | |
| First Time appeared |
Weidmueller
Weidmueller fwr Ie Sr 2tx Wl 4g Eu Us |
|
| Weaknesses | CWE-288 | |
| CPEs | cpe:2.3:o:weidmueller:fwr_ie_sr_2tx_wl_4g_eu_us:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Weidmueller
Weidmueller fwr Ie Sr 2tx Wl 4g Eu Us |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-08-25T08:55:12.442Z
Reserved: 2026-07-17T06:47:50.712Z
Link: CVE-2026-63587
No data.
Status : Received
Published: 2026-08-25T09:17:32.057
Modified: 2026-08-25T09:17:32.057
Link: CVE-2026-63587
No data.
OpenCVE Enrichment
Updated: 2026-08-25T10:30:05Z
-
CWE-288
Authentication Bypass Using an Alternate Path or Channel