Answer in brief
CVE-2026-63587 records a High severity (CVSS 8.6) vulnerability in SMS Password Authorization Bypass via Failed Attempt Counter. The current sources do not mark it as known exploited. The current feed maps Weidmueller Interface/IE-SR-2TX-WL-4G-EU (generic), Weidmueller Interface/IE-SR-2TX-WL-4G-US-V (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.6. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Weidmueller Interface/IE-SR-2TX-WL-4G-EU (generic), Weidmueller Interface/IE-SR-2TX-WL-4G-US-V (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Weidmueller Interface/IE-SR-2TX-WL-4G-EUgeneric | >=1.67 <1.74 | 1.74 |
| Weidmueller Interface/IE-SR-2TX-WL-4G-US-Vgeneric | >=1.67 <1.74 | 1.74 |
Published upstream
Aug 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 3, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 25, 2026
The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliberately trigger this by submitting 5 or more invalid passwords, after which subsequent SMS commands are executed without requiring a password, resulting in potential limited configuration tampering, limited information leakage and potentially full loss of availability.
Quoted source text, attributed separately from HOL analysis.