<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>IE-SR - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/ie-sr/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 25 Aug 2026 12:08:01 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/ie-sr/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in IE-SR-2TX-WL-4G via SMS Retry Mechanism</title><link>https://feed.craftedsignal.io/briefs/2026-08-sms-auth-bypass/</link><pubDate>Tue, 25 Aug 2026 12:08:01 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-sms-auth-bypass/</guid><description>An authentication bypass vulnerability in IE-SR-2TX-WL-4G devices allows unauthenticated attackers to disable SMS password protection by triggering a fail-retry counter, leading to unauthorized command execution.</description><content:encoded><![CDATA[<p>The IE-SR-2TX-WL-4G gateway contains a critical authentication vulnerability regarding its SMS control function. When the 'Enable Password Authorization' feature is active, the device tracks failed authentication attempts. A flaw in the design causes the device to automatically disable the requirement for a password after five consecutive failed attempts. An unauthenticated attacker capable of sending SMS messages to the device can exploit this by submitting five invalid password commands. Once the counter reaches the threshold, the device drops the authentication requirement for all subsequent SMS commands, granting the attacker the ability to tamper with configurations, leak device information, or cause a full denial of service. This vulnerability is significant as it provides remote, unauthenticated access to the gateway via the cellular network interface.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an unauthenticated remote attacker to gain administrative control over the affected device via SMS. Potential damage includes unauthorized configuration changes, exfiltration of device-specific information, and total loss of availability through disruptive command execution, impacting industrial or remote networking environments where these gateways are deployed.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams:</p>
<ul>
<li>Verify if 'Enable Password Authorization' is currently enforced on all deployed IE-SR-2TX-WL-4G units.</li>
<li>Review documentation for firmware updates from the vendor to address the retry counter logic.</li>
<li>Implement cellular network-level SMS filtering to restrict the sender source for all managed gateways, preventing unauthorized remote access.</li>
<li>Audit device configuration logs for recurring patterns of failed SMS password attempts which may indicate exploitation attempts.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>