CyberRota Analysis
AI-GeneratedThe firmware of the CSL 1010 M2M 3G WiFi Module, up to version 2.2.1.4, contains a weak encryption vulnerability that allows unauthenticated attackers to easily decrypt sensitive configuration files, exposing critical credentials such as web administration passwords and SIM identifiers. This vulnerability poses a medium severity risk, as it enables attackers to gain unauthorized access to network configurations and potentially compromise connected devices. Organizations using this module should prioritize patching or upgrading their firmware to mitigate the risk of credential theft and unauthorized access.
Original NVD Description
CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticated attackers to recover all stored secrets in plaintext by reversing a single-byte XOR cipher that uses a static key to obfuscate the configuration backup file. Attackers can trivially decrypt the Router.cfg backup file to expose web administration and telnet passwords, WPA/WPA2 pre-shared keys, PPPoE and 3G/APN credentials, and SIM identifiers including IMSI and IMEI.