CVE-2026-63587: SMS Password Authorization Bypass via Failed Attempt Counter
The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliberately trigger this by submitting 5 or more invalid passwords, after which subsequent SMS commands are executed without requiring a password, resulting in potential limited configuration tampering, limited information leakage and potentially full loss of availability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
In the IE-SR-2TX-WL-4G device SMS control settings, enable the setting 'Enable Password Authorization' so SMS commands require a password.
IE-SR-2TX-WL-4G device (SMS control function) Enable Password Authorization = Enabled
Event History
Frequently Asked Questions
Which devices and configurations are exposed?
IE-SR-2TX-WL-4G devices are affected when their SMS control function is enabled and the “Enable Password Authorization” setting is used to require a password for SMS commands.
What does an attacker need to exploit this issue?
The attacker needs only to be able to send SMS messages to the device. No valid SMS password, prior authentication, or user interaction is required.
How is password protection bypassed?
An attacker can send five or more SMS commands containing invalid passwords. After five consecutive failed attempts, the device automatically disables SMS password authorization, allowing later SMS commands to run without a password.
What could indicate that a device has already been targeted?
Five consecutive failed SMS password attempts may have caused SMS password authorization to become disabled. Verify whether the setting remains enabled and review available SMS-command or device configuration records for failed attempts and unauthorized command activity.
What can be done if a patch is not immediately available?
Restrict who can send SMS messages to the device where possible, since SMS delivery capability is the required access condition. Monitor the password-authorization setting and re-enable it if it has been disabled after failed attempts.