{"document":{"acknowledgments":[{"organization":"CERT@VDE","summary":"coordination","urls":["https://certvde.com"]},{"organization":"diconium auto GmbH","summary":"Penetration testing","urls":["https://www.diconium.com"]}],"aggregate_severity":{"namespace":"https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale","text":"Critical"},"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en-GB","notes":[{"category":"summary","text":"Weidmueller security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by an unauthenticated remote code execution vulnerability. IE-SR-2TX-WL-4G routers are also affected by a SMS password authorization bypass vulnerability.\n\nWeidmueller has released new firmware versions of the affected products to fix the vulnerabilities.","title":"Summary"},{"category":"description","text":"An attacker with network access to the device can execute arbitrary shell commands with root privileges without authentication, by injecting a specially crafted username into the HTTP Basic Authentication header used by the web management interface. This can be used, for example, to overwrite a script exposed on the web server and create a persistent backdoor.\n\nAdditionally, an attacker able to send SMS messages to the IE-SR-2TX-WL-4G variants can disable SMS password authorization by repeatedly submitting invalid passwords (5 or more), after which any SMS command is executed without requiring a password. Commands are limited to availability functions.","title":"Impact"},{"category":"description","text":"Until the firmware update is installed, affected users are strongly advised to:\n- Restrict access to the web management interface using firewall rules, access control lists (ACLs), a VPN, or a trusted management network, and ensure the interface is not directly exposed to the public internet.\n- Disable the \"Enable reception of SMS control messages\" function on IE-SR-2TX-WL-4G devices to prevent unauthorized SMS commands from being executed.","title":"Mitigation"},{"category":"description","text":"Update to the new version as listed in the following table:\n\n| Product              | Article Number | Firmware File Name         | Affected Version | Fixed Version |\n|-----------------------|-----------------|-------------------------------|------------------|---------------|\n| IE-SR-2TX-WL          | 2682590000      | FWR_IE-SR-2TX-WL              | <V1.57           | V1.57         |\n| IE-SR-2TX-WL-4G-EU    | 2682560000      | FWR_IE-SR-2TX-WL-4G-EU_US     | <V1.74           | V1.74         |\n| IE-SR-2TX-WL-4G-US-V  | 2682580000      | FWR_IE-SR-2TX-WL-4G-EU_US     | <V1.74           | V1.74         |\n","title":"Remediation"},{"category":"general","text":"As a general security measure, Weidmueller strongly recommends to change the default passwords and to minimize the network exposure of products. Limit access to trusted networks by using the appropriate mechanisms.","title":"General Recommendation"}],"publisher":{"category":"vendor","contact_details":"psirt@weidmueller.com","name":"Weidmueller Interface GmbH & Co. KG","namespace":"https://www.weidmueller.com"},"references":[{"category":"external","summary":"Weidmueller Security Advisory Board","url":"https://support.weidmueller.com/support-center/popular-resources/security-advisory-board"},{"category":"external","summary":"CERT@VDE Security Advisories for Weidmueller","url":"https://certvde.com/de/advisories/vendor/weidmueller/"},{"category":"self","summary":"VDE-2026-083: Weidmueller: Security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by multiple vulnerabilities - HTML","url":"https://certvde.com/de/advisories/VDE-2026-083"},{"category":"self","summary":"VDE-2026-083: Weidmueller: Security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by multiple vulnerabilities - CSAF","url":"https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-083.json"}],"title":"Weidmueller: Security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by multiple vulnerabilities","tracking":{"aliases":["VDE-2026-083","WMSA-2600002"],"current_release_date":"2026-08-25T09:00:00.000Z","generator":{"date":"2026-08-24T00:00:00.000Z","engine":{"name":"psirt-advisory-engine","version":"2.0"}},"id":"VDE-2026-083","initial_release_date":"2026-08-25T09:00:00.000Z","revision_history":[{"date":"2026-08-25T09:00:00.000Z","number":"1.0.0","summary":"Initial version"}],"status":"final","version":"1.0.0"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"IE-SR-2TX-WL","product":{"name":"IE-SR-2TX-WL","product_id":"CSAFPID-11001","product_identification_helper":{"cpe":"cpe:2.3:h:weidmueller:ie-sr-2tx-wl:*:*:*:*:*:*:*:*","model_numbers":["2682590000"]}}},{"category":"product_name","name":"IE-SR-2TX-WL-4G-EU","product":{"name":"IE-SR-2TX-WL-4G-EU","product_id":"CSAFPID-11002","product_identification_helper":{"cpe":"cpe:2.3:h:weidmueller:ie-sr-2tx-wl-4g-eu:*:*:*:*:*:*:*:*","model_numbers":["2682560000"]}}},{"category":"product_name","name":"IE-SR-2TX-WL-4G-US-V","product":{"name":"IE-SR-2TX-WL-4G-US-V","product_id":"CSAFPID-11003","product_identification_helper":{"cpe":"cpe:2.3:h:weidmueller:ie-sr-2tx-wl-4g-us-v:*:*:*:*:*:*:*:*","model_numbers":["2682580000"]}}}],"category":"product_family","name":"Hardware"},{"branches":[{"category":"product_version_range","name":"vers:generic/>=1.52|<1.57","product":{"name":"IE-SR-2TX-WL Firmware 1.52 < V1.57","product_id":"CSAFPID-21001","product_identification_helper":{"cpe":"cpe:2.3:o:weidmueller:fwr_ie-sr-2tx-wl:*:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"vers:generic/>=1.67|<1.74","product":{"name":"IE-SR-2TX-WL-4G Firmware 1.67 < V1.74","product_id":"CSAFPID-21002","product_identification_helper":{"cpe":"cpe:2.3:o:weidmueller:fwr_ie-sr-2tx-wl-4g-eu_us:*:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"V1.57","product":{"name":"IE-SR-2TX-WL Firmware V1.57","product_id":"CSAFPID-22001","product_identification_helper":{"cpe":"cpe:2.3:o:weidmueller:fwr_ie-sr-2tx-wl:1.57:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"V1.74","product":{"name":"IE-SR-2TX-WL-4G Firmware V1.74","product_id":"CSAFPID-22002","product_identification_helper":{"cpe":"cpe:2.3:o:weidmueller:fwr_ie-sr-2tx-wl-4g-eu_us:1.74:*:*:*:*:*:*:*"}}}],"category":"product_family","name":"Firmware"}],"category":"vendor","name":"Weidmueller"}],"product_groups":[{"group_id":"CSAFGID-0001","product_ids":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"],"summary":"Affected products."},{"group_id":"CSAFGID-0002","product_ids":["CSAFPID-32001","CSAFPID-32002","CSAFPID-32003"],"summary":"Fixed products."},{"group_id":"CSAFGID-0003","product_ids":["CSAFPID-31002","CSAFPID-31003"],"summary":"Affected products (IE-SR-2TX-WL-4G variants only)."},{"group_id":"CSAFGID-0004","product_ids":["CSAFPID-32002","CSAFPID-32003"],"summary":"Fixed products (IE-SR-2TX-WL-4G variants only)."}],"relationships":[{"category":"installed_on","full_product_name":{"name":"IE-SR-2TX-WL Firmware 1.52 < V1.57 installed on IE-SR-2TX-WL","product_id":"CSAFPID-31001","product_identification_helper":{"cpe":"cpe:2.3:o:weidmueller:fwr_ie-sr-2tx-wl:*:*:*:*:*:*:*:*"}},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11001"},{"category":"installed_on","full_product_name":{"name":"IE-SR-2TX-WL-4G Firmware 1.67 < V1.74 installed on IE-SR-2TX-WL-4G-EU","product_id":"CSAFPID-31002","product_identification_helper":{"cpe":"cpe:2.3:o:weidmueller:fwr_ie-sr-2tx-wl-4g-eu_us:*:*:*:*:*:*:*:*"}},"product_reference":"CSAFPID-21002","relates_to_product_reference":"CSAFPID-11002"},{"category":"installed_on","full_product_name":{"name":"IE-SR-2TX-WL-4G Firmware 1.67 < V1.74 installed on IE-SR-2TX-WL-4G-US-V","product_id":"CSAFPID-31003","product_identification_helper":{"cpe":"cpe:2.3:o:weidmueller:fwr_ie-sr-2tx-wl-4g-eu_us:*:*:*:*:*:*:*:*"}},"product_reference":"CSAFPID-21002","relates_to_product_reference":"CSAFPID-11003"},{"category":"installed_on","full_product_name":{"name":"IE-SR-2TX-WL Firmware V1.57 installed on IE-SR-2TX-WL","product_id":"CSAFPID-32001","product_identification_helper":{"cpe":"cpe:2.3:o:weidmueller:fwr_ie-sr-2tx-wl:1.57:*:*:*:*:*:*:*"}},"product_reference":"CSAFPID-22001","relates_to_product_reference":"CSAFPID-11001"},{"category":"installed_on","full_product_name":{"name":"IE-SR-2TX-WL-4G Firmware V1.74 installed on IE-SR-2TX-WL-4G-EU","product_id":"CSAFPID-32002","product_identification_helper":{"cpe":"cpe:2.3:o:weidmueller:fwr_ie-sr-2tx-wl-4g-eu_us:1.74:*:*:*:*:*:*:*"}},"product_reference":"CSAFPID-22002","relates_to_product_reference":"CSAFPID-11002"},{"category":"installed_on","full_product_name":{"name":"IE-SR-2TX-WL-4G Firmware V1.74 installed on IE-SR-2TX-WL-4G-US-V","product_id":"CSAFPID-32003","product_identification_helper":{"cpe":"cpe:2.3:o:weidmueller:fwr_ie-sr-2tx-wl-4g-eu_us:1.74:*:*:*:*:*:*:*"}},"product_reference":"CSAFPID-22002","relates_to_product_reference":"CSAFPID-11003"}]},"vulnerabilities":[{"cve":"CVE-2026-63586","cwe":{"id":"CWE-78","name":"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"},"notes":[{"audience":"all","category":"description","text":"The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is inserted into a shell command string executed via the system() function. By submitting a specially crafted username containing shell metacharacters, an unauthenticated attacker with network access to the device can escape the command context and execute arbitrary commands with root privileges.","title":"CVE description"}],"product_status":{"fixed":["CSAFPID-32001","CSAFPID-32002","CSAFPID-32003"],"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]},"references":[{"category":"external","summary":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - 9.3 / Critical","url":"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"remediations":[{"category":"mitigation","details":"Restrict access to the web management interface using firewall rules, access control lists (ACLs), a VPN, or a trusted management network, and ensure the interface is not directly exposed to the public internet, until the firmware update is installed.","group_ids":["CSAFGID-0001"]},{"category":"vendor_fix","details":"Update to the fixed firmware version listed in the remediation table.","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","environmentalScore":9.8,"environmentalSeverity":"CRITICAL","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":9.8,"temporalSeverity":"CRITICAL","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]}],"title":"Unauthenticated Remote Code Execution via Shell Injection in Web Management Interface"},{"cve":"CVE-2026-63587","cwe":{"id":"CWE-288","name":"Authentication Bypass Using an Alternate Path or Channel"},"notes":[{"audience":"all","category":"description","text":"The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliberately trigger this by submitting 5 or more invalid passwords, after which subsequent SMS commands are executed without requiring a password, resulting in potential limited configuration tampering, limited information leakage and potentially full loss of availability. ","title":"CVE description"}],"product_status":{"fixed":["CSAFPID-32002","CSAFPID-32003"],"known_affected":["CSAFPID-31002","CSAFPID-31003"]},"references":[{"category":"external","summary":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N - 8.8 / High","url":"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N"}],"remediations":[{"category":"mitigation","details":"Disable the \"Enable reception of SMS control messages\" function on IE-SR-2TX-WL-4G devices to prevent unauthorized SMS commands from being executed, until the firmware update is installed.","group_ids":["CSAFGID-0003"]},{"category":"vendor_fix","details":"Update to the fixed firmware version listed in the remediation table.","group_ids":["CSAFGID-0003"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.6,"baseSeverity":"HIGH","confidentialityImpact":"LOW","environmentalScore":8.6,"environmentalSeverity":"HIGH","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":8.6,"temporalSeverity":"HIGH","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","version":"3.1"},"products":["CSAFPID-31002","CSAFPID-31003"]}],"title":"SMS Password Authorization Bypass via Failed Attempt Counter"}]}