Zurück zur Übersicht

Weidmueller: Security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by multiple vulnerabilities

VDE-2026-083
Last update
25.08.2026 11:00
Published at
25.08.2026 11:00
Vendor(s)
Weidmueller Interface GmbH & Co. KG
External ID
VDE-2026-083
CSAF Document

Summary

Weidmueller security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by an unauthenticated remote code execution vulnerability. IE-SR-2TX-WL-4G routers are also affected by a SMS password authorization bypass vulnerability.

Weidmueller has released new firmware versions of the affected products to fix the vulnerabilities.

Impact

An attacker with network access to the device can execute arbitrary shell commands with root privileges without authentication, by injecting a specially crafted username into the HTTP Basic Authentication header used by the web management interface. This can be used, for example, to overwrite a script exposed on the web server and create a persistent backdoor.

Additionally, an attacker able to send SMS messages to the IE-SR-2TX-WL-4G variants can disable SMS password authorization by repeatedly submitting invalid passwords (5 or more), after which any SMS command is executed without requiring a password. Commands are limited to availability functions.

Affected Product(s)

Model no. Product name Affected versions
2682590000 IE-SR-2TX-WL IE-SR-2TX-WL Firmware 1.52 < V1.57
2682560000 IE-SR-2TX-WL-4G-EU IE-SR-2TX-WL-4G Firmware 1.67 < V1.74
2682580000 IE-SR-2TX-WL-4G-US-V IE-SR-2TX-WL-4G Firmware 1.67 < V1.74

Vulnerabilities

Expand / Collapse all

Published
25.08.2026 11:00
Weakness
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Summary

The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is inserted into a shell command string executed via the system() function. By submitting a specially crafted username containing shell metacharacters, an unauthenticated attacker with network access to the device can escape the command context and execute arbitrary commands with root privileges.

References

Published
25.08.2026 11:00
Weakness
Authentication Bypass Using an Alternate Path or Channel (CWE-288)
Summary

The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliberately trigger this by submitting 5 or more invalid passwords, after which subsequent SMS commands are executed without requiring a password, resulting in potential limited configuration tampering, limited information leakage and potentially full loss of availability.

References

Mitigation

Until the firmware update is installed, affected users are strongly advised to:
- Restrict access to the web management interface using firewall rules, access control lists (ACLs), a VPN, or a trusted management network, and ensure the interface is not directly exposed to the public internet.
- Disable the "Enable reception of SMS control messages" function on IE-SR-2TX-WL-4G devices to prevent unauthorized SMS commands from being executed.

Remediation

Update to the new version as listed in the following table:

Product Article Number Firmware File Name Affected Version Fixed Version
IE-SR-2TX-WL 2682590000 FWR_IE-SR-2TX-WL

Acknowledgments

Weidmueller Interface GmbH & Co. KG thanks the following parties for their efforts:

Revision History

Version Date Summary
1.0.0 25.08.2026 11:00 Initial version