{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/ie-sr/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.6,"id":"CVE-2026-63587"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["IE-SR-2TX-WL-4G"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["IE-SR"],"content_html":"\u003cp\u003eThe IE-SR-2TX-WL-4G gateway contains a critical authentication vulnerability regarding its SMS control function. When the 'Enable Password Authorization' feature is active, the device tracks failed authentication attempts. A flaw in the design causes the device to automatically disable the requirement for a password after five consecutive failed attempts. An unauthenticated attacker capable of sending SMS messages to the device can exploit this by submitting five invalid password commands. Once the counter reaches the threshold, the device drops the authentication requirement for all subsequent SMS commands, granting the attacker the ability to tamper with configurations, leak device information, or cause a full denial of service. This vulnerability is significant as it provides remote, unauthenticated access to the gateway via the cellular network interface.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated remote attacker to gain administrative control over the affected device via SMS. Potential damage includes unauthorized configuration changes, exfiltration of device-specific information, and total loss of availability through disruptive command execution, impacting industrial or remote networking environments where these gateways are deployed.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eVerify if 'Enable Password Authorization' is currently enforced on all deployed IE-SR-2TX-WL-4G units.\u003c/li\u003e\n\u003cli\u003eReview documentation for firmware updates from the vendor to address the retry counter logic.\u003c/li\u003e\n\u003cli\u003eImplement cellular network-level SMS filtering to restrict the sender source for all managed gateways, preventing unauthorized remote access.\u003c/li\u003e\n\u003cli\u003eAudit device configuration logs for recurring patterns of failed SMS password attempts which may indicate exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-25T12:08:01Z","date_published":"2026-08-25T12:08:01Z","id":"https://feed.craftedsignal.io/briefs/2026-08-sms-auth-bypass/","summary":"An authentication bypass vulnerability in IE-SR-2TX-WL-4G devices allows unauthenticated attackers to disable SMS password protection by triggering a fail-retry counter, leading to unauthorized command execution.","title":"Authentication Bypass in IE-SR-2TX-WL-4G via SMS Retry Mechanism","url":"https://feed.craftedsignal.io/briefs/2026-08-sms-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - IE-SR","version":"https://jsonfeed.org/version/1.1"}