Summary
Weidmueller security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by an unauthenticated remote code execution vulnerability. IE-SR-2TX-WL-4G routers are also affected by a SMS password authorization bypass vulnerability.
Weidmueller has released new firmware versions of the affected products to fix the vulnerabilities.
Impact
An attacker with network access to the device can execute arbitrary shell commands with root privileges without authentication, by injecting a specially crafted username into the HTTP Basic Authentication header used by the web management interface. This can be used, for example, to overwrite a script exposed on the web server and create a persistent backdoor.
Additionally, an attacker able to send SMS messages to the IE-SR-2TX-WL-4G variants can disable SMS password authorization by repeatedly submitting invalid passwords (5 or more), after which any SMS command is executed without requiring a password. Commands are limited to availability functions.
Affected Product(s)
| Model no. | Product name | Affected versions |
|---|---|---|
| 2682590000 | IE-SR-2TX-WL | IE-SR-2TX-WL Firmware 1.52 < V1.57 |
| 2682560000 | IE-SR-2TX-WL-4G-EU | IE-SR-2TX-WL-4G Firmware 1.67 < V1.74 |
| 2682580000 | IE-SR-2TX-WL-4G-US-V | IE-SR-2TX-WL-4G Firmware 1.67 < V1.74 |
Vulnerabilities
Expand / Collapse allThe web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is inserted into a shell command string executed via the system() function. By submitting a specially crafted username containing shell metacharacters, an unauthenticated attacker with network access to the device can escape the command context and execute arbitrary commands with root privileges.
The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliberately trigger this by submitting 5 or more invalid passwords, after which subsequent SMS commands are executed without requiring a password, resulting in potential limited configuration tampering, limited information leakage and potentially full loss of availability.
Mitigation
Until the firmware update is installed, affected users are strongly advised to:
- Restrict access to the web management interface using firewall rules, access control lists (ACLs), a VPN, or a trusted management network, and ensure the interface is not directly exposed to the public internet.
- Disable the "Enable reception of SMS control messages" function on IE-SR-2TX-WL-4G devices to prevent unauthorized SMS commands from being executed.
Remediation
Update to the new version as listed in the following table:
| Product | Article Number | Firmware File Name | Affected Version | Fixed Version |
|---|---|---|---|---|
| IE-SR-2TX-WL | 2682590000 | FWR_IE-SR-2TX-WL |
Acknowledgments
Weidmueller Interface GmbH & Co. KG thanks the following parties for their efforts:
- CERT@VDE for coordination (see https://certvde.com )
- diconium auto GmbH for Penetration testing (see https://www.diconium.com )
Revision History
| Version | Date | Summary |
|---|---|---|
| 1.0.0 | 25.08.2026 11:00 | Initial version |