CVE-2026-63587: SMS Password Authorization Bypass via Failed Attempt Counter

Published Aug 25, 2026
·
Updated

The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliberately trigger this by submitting 5 or more invalid passwords, after which subsequent SMS commands are executed without requiring a password, resulting in potential limited configuration tampering, limited information leakage and potentially full loss of availability.

Affected Software

1 affected component
IE-SR-2TX-WL-4G

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    In the IE-SR-2TX-WL-4G device SMS control settings, enable the setting 'Enable Password Authorization' so SMS commands require a password.

    IE-SR-2TX-WL-4G device (SMS control function) Enable Password Authorization = Enabled

Event History

Aug 25, 2026
CVE Published
via MITRE·08:55 AM
Data Sourced
via MITRE·08:55 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which devices and configurations are exposed?

IE-SR-2TX-WL-4G devices are affected when their SMS control function is enabled and the “Enable Password Authorization” setting is used to require a password for SMS commands.

2

What does an attacker need to exploit this issue?

The attacker needs only to be able to send SMS messages to the device. No valid SMS password, prior authentication, or user interaction is required.

3

How is password protection bypassed?

An attacker can send five or more SMS commands containing invalid passwords. After five consecutive failed attempts, the device automatically disables SMS password authorization, allowing later SMS commands to run without a password.

4

What could indicate that a device has already been targeted?

Five consecutive failed SMS password attempts may have caused SMS password authorization to become disabled. Verify whether the setting remains enabled and review available SMS-command or device configuration records for failed attempts and unauthorized command activity.

5

What can be done if a patch is not immediately available?

Restrict who can send SMS messages to the device where possible, since SMS delivery capability is the required access condition. Monitor the password-authorization setting and re-enable it if it has been disabled after failed attempts.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203