SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-63587

HIGH · CVSS 8.6 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The SMS control function in IE-SR-2TX-WL-4G devices is vulnerable due to a flaw in the password authorization mechanism, allowing an unauthenticated remote attacker to disable SMS password protection by sending five consecutive invalid password attempts. This exploitation can lead to unauthorized execution of SMS commands, resulting in limited configuration tampering, information leakage, and potential denial of service. Organizations using these devices should prioritize patching this vulnerability to safeguard against potential attacks.

CVE
CVE-2026-63587
Severity
HIGH
CVSS
8.6
EPSS
0.27%

Original NVD Description

The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliberately trigger this by submitting 5 or more invalid passwords, after which subsequent SMS commands are executed without requiring a password, resulting in potential limited configuration tampering, limited information leakage and potentially full loss of availability.