WMSA-2600002
Weidmueller Security Advisory by Weidmueller PSIRT

Weidmueller: Security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by multiple vulnerabilities

Publisher: Weidmueller Interface GmbH & Co. KG Document category: csaf_security_advisory
Initial release date: 2026-08-25T09:00:00.000Z Engine: psirt-advisory-engine 2.0
Current release date: 2026-08-25T09:00:00.000Z Build Date: 2026-08-24T00:00:00.000Z
Current version: 1.0.0 Status: final
CVSSv3.1 Base Score: 9.8 Severity: Critical
Original language: Language: en-GB
Also referred to: VDE-2026-083, WMSA-2600002

Summary

Weidmueller security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by an unauthenticated remote code execution vulnerability. IE-SR-2TX-WL-4G routers are also affected by a SMS password authorization bypass vulnerability.

Weidmueller has released new firmware versions of the affected products to fix the vulnerabilities.

General Recommendation

As a general security measure, Weidmueller strongly recommends to change the default passwords and to minimize the network exposure of products. Limit access to trusted networks by using the appropriate mechanisms.

Impact

An attacker with network access to the device can execute arbitrary shell commands with root privileges without authentication, by injecting a specially crafted username into the HTTP Basic Authentication header used by the web management interface. This can be used, for example, to overwrite a script exposed on the web server and create a persistent backdoor.

Additionally, an attacker able to send SMS messages to the IE-SR-2TX-WL-4G variants can disable SMS password authorization by repeatedly submitting invalid passwords (5 or more), after which any SMS command is executed without requiring a password. Commands are limited to availability functions.

Mitigation

Until the firmware update is installed, affected users are strongly advised to: - Restrict access to the web management interface using firewall rules, access control lists (ACLs), a VPN, or a trusted management network, and ensure the interface is not directly exposed to the public internet. - Disable the "Enable reception of SMS control messages" function on IE-SR-2TX-WL-4G devices to prevent unauthorized SMS commands from being executed.

Remediation

Update to the new version as listed in the following table:

ProductArticle NumberFirmware File NameAffected VersionFixed Version
IE-SR-2TX-WL2682590000FWR_IE-SR-2TX-WL<V1.57V1.57
IE-SR-2TX-WL-4G-EU2682560000FWR_IE-SR-2TX-WL-4G-EU_US<V1.74V1.74
IE-SR-2TX-WL-4G-US-V2682580000FWR_IE-SR-2TX-WL-4G-EU_US<V1.74V1.74

Product groups

Affected products. Fixed products. Affected products (IE-SR-2TX-WL-4G variants only). Fixed products (IE-SR-2TX-WL-4G variants only).

Vulnerabilities

Unauthenticated Remote Code Execution via Shell Injection in Web Management Interface (CVE-2026-63586)
CVE Description

The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is inserted into a shell command string executed via the system() function. By submitting a specially crafted username containing shell metacharacters, an unauthenticated attacker with network access to the device can escape the command context and execute arbitrary commands with root privileges.

CVSS Score:9.8 (CRITICAL) - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE:CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
  • IE-SR-2TX-WL Firmware 1.52 < V1.57 installed on IE-SR-2TX-WL
  • IE-SR-2TX-WL-4G Firmware 1.67 < V1.74 installed on IE-SR-2TX-WL-4G-EU
  • IE-SR-2TX-WL-4G Firmware 1.67 < V1.74 installed on IE-SR-2TX-WL-4G-US-V
  • IE-SR-2TX-WL Firmware V1.57 installed on IE-SR-2TX-WL
  • IE-SR-2TX-WL-4G Firmware V1.74 installed on IE-SR-2TX-WL-4G-EU
  • IE-SR-2TX-WL-4G Firmware V1.74 installed on IE-SR-2TX-WL-4G-US-V

Remediations

Mitigation

Restrict access to the web management interface using firewall rules, access control lists (ACLs), a VPN, or a trusted management network, and ensure the interface is not directly exposed to the public internet, until the firmware update is installed.

Vendor fix

Update to the fixed firmware version listed in the remediation table.

SMS Password Authorization Bypass via Failed Attempt Counter (CVE-2026-63587)
CVE Description

The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliberately trigger this by submitting 5 or more invalid passwords, after which subsequent SMS commands are executed without requiring a password, resulting in potential limited configuration tampering, limited information leakage and potentially full loss of availability.

CVSS Score:8.6 (HIGH) - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
CWE:CWE-288: Authentication Bypass Using an Alternate Path or Channel
  • IE-SR-2TX-WL-4G Firmware 1.67 < V1.74 installed on IE-SR-2TX-WL-4G-EU
  • IE-SR-2TX-WL-4G Firmware 1.67 < V1.74 installed on IE-SR-2TX-WL-4G-US-V
  • IE-SR-2TX-WL-4G Firmware V1.74 installed on IE-SR-2TX-WL-4G-EU
  • IE-SR-2TX-WL-4G Firmware V1.74 installed on IE-SR-2TX-WL-4G-US-V

Remediations

Mitigation

Disable the "Enable reception of SMS control messages" function on IE-SR-2TX-WL-4G devices to prevent unauthorized SMS commands from being executed, until the firmware update is installed.

Vendor fix

Update to the fixed firmware version listed in the remediation table.

Acknowledgments

Weidmueller Interface GmbH & Co. KG thanks the following parties for their efforts:

Weidmueller Interface GmbH & Co. KG

Namespace: https://www.weidmueller.com

psirt@weidmueller.com

References

Revision history

Version Date of the revision Summary of the revision
1.0.02026-08-25T09:00:00.000ZInitial version

Sharing rules

TLP:WHITE
For the TLP version see: https://www.first.org/tlp/