Authentication Bypass in IE-SR-2TX-WL-4G via SMS Retry Mechanism
An authentication bypass vulnerability in IE-SR-2TX-WL-4G devices allows unauthenticated attackers to disable SMS password protection by triggering a fail-retry counter, leading to unauthorized command execution.
CVE search metadata
CVE search record: CVE-2026-63587. Severity: high. CVSS: 8.6. KEV: no. Product: IE-SR-2TX-WL-4G. Brief: Authentication Bypass in IE-SR-2TX-WL-4G via SMS Retry Mechanism. Brief link: https://feed.craftedsignal.io/briefs/2026-08-sms-auth-bypass/
The IE-SR-2TX-WL-4G gateway contains a critical authentication vulnerability regarding its SMS control function. When the 'Enable Password Authorization' feature is active, the device tracks failed authentication attempts. A flaw in the design causes the device to automatically disable the requirement for a password after five consecutive failed attempts. An unauthenticated attacker capable of sending SMS messages to the device can exploit this by submitting five invalid password commands. Once the counter reaches the threshold, the device drops the authentication requirement for all subsequent SMS commands, granting the attacker the ability to tamper with configurations, leak device information, or cause a full denial of service. This vulnerability is significant as it provides remote, unauthenticated access to the gateway via the cellular network interface.
Impact
Successful exploitation allows an unauthenticated remote attacker to gain administrative control over the affected device via SMS. Potential damage includes unauthorized configuration changes, exfiltration of device-specific information, and total loss of availability through disruptive command execution, impacting industrial or remote networking environments where these gateways are deployed.
Recommendation
Prioritized actions for security teams:
- Verify if 'Enable Password Authorization' is currently enforced on all deployed IE-SR-2TX-WL-4G units.
- Review documentation for firmware updates from the vendor to address the retry counter logic.
- Implement cellular network-level SMS filtering to restrict the sender source for all managed gateways, preventing unauthorized remote access.
- Audit device configuration logs for recurring patterns of failed SMS password attempts which may indicate exploitation attempts.
Immediate actions
Review cellular gateway configurations to verify if password authorization is active
Mitigations
Restrict SMS sender sources at the carrier level if possible
CVE-2026-63587