| Publisher: Weidmueller Interface GmbH & Co. KG | Document category: csaf_security_advisory |
| Initial release date: 2026-08-25T09:00:00.000Z | Engine: psirt-advisory-engine 2.0 |
| Current release date: 2026-08-25T09:00:00.000Z | Build Date: 2026-08-24T00:00:00.000Z |
| Current version: 1.0.0 | Status: final |
| CVSSv3.1 Base Score: 9.8 | Severity: Critical |
| Original language: | Language: en-GB |
| Also referred to: VDE-2026-083, WMSA-2600002 | |
Weidmueller security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by an unauthenticated remote code execution vulnerability. IE-SR-2TX-WL-4G routers are also affected by a SMS password authorization bypass vulnerability.
Weidmueller has released new firmware versions of the affected products to fix the vulnerabilities.
As a general security measure, Weidmueller strongly recommends to change the default passwords and to minimize the network exposure of products. Limit access to trusted networks by using the appropriate mechanisms.
An attacker with network access to the device can execute arbitrary shell commands with root privileges without authentication, by injecting a specially crafted username into the HTTP Basic Authentication header used by the web management interface. This can be used, for example, to overwrite a script exposed on the web server and create a persistent backdoor.
Additionally, an attacker able to send SMS messages to the IE-SR-2TX-WL-4G variants can disable SMS password authorization by repeatedly submitting invalid passwords (5 or more), after which any SMS command is executed without requiring a password. Commands are limited to availability functions.
Until the firmware update is installed, affected users are strongly advised to: - Restrict access to the web management interface using firewall rules, access control lists (ACLs), a VPN, or a trusted management network, and ensure the interface is not directly exposed to the public internet. - Disable the "Enable reception of SMS control messages" function on IE-SR-2TX-WL-4G devices to prevent unauthorized SMS commands from being executed.
Update to the new version as listed in the following table:
| Product | Article Number | Firmware File Name | Affected Version | Fixed Version |
|---|---|---|---|---|
| IE-SR-2TX-WL | 2682590000 | FWR_IE-SR-2TX-WL | <V1.57 | V1.57 |
| IE-SR-2TX-WL-4G-EU | 2682560000 | FWR_IE-SR-2TX-WL-4G-EU_US | <V1.74 | V1.74 |
| IE-SR-2TX-WL-4G-US-V | 2682580000 | FWR_IE-SR-2TX-WL-4G-EU_US | <V1.74 | V1.74 |
The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is inserted into a shell command string executed via the system() function. By submitting a specially crafted username containing shell metacharacters, an unauthenticated attacker with network access to the device can escape the command context and execute arbitrary commands with root privileges.
| CVSS Score: | 9.8 (CRITICAL) - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
|---|---|
| CWE: | CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') |
Known affected
Fixed
Restrict access to the web management interface using firewall rules, access control lists (ACLs), a VPN, or a trusted management network, and ensure the interface is not directly exposed to the public internet, until the firmware update is installed.
Update to the fixed firmware version listed in the remediation table.
References
The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliberately trigger this by submitting 5 or more invalid passwords, after which subsequent SMS commands are executed without requiring a password, resulting in potential limited configuration tampering, limited information leakage and potentially full loss of availability.
| CVSS Score: | 8.6 (HIGH) - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H |
|---|---|
| CWE: | CWE-288: Authentication Bypass Using an Alternate Path or Channel |
Known affected
Fixed
Disable the "Enable reception of SMS control messages" function on IE-SR-2TX-WL-4G devices to prevent unauthorized SMS commands from being executed, until the firmware update is installed.
Update to the fixed firmware version listed in the remediation table.
References
Namespace: https://www.weidmueller.com
psirt@weidmueller.com
| Version | Date of the revision | Summary of the revision |
|---|---|---|
| 1.0.0 | 2026-08-25T09:00:00.000Z | Initial version |
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/