Weidmueller recently published a security advisory addressing a critical Weidmueller router flaw alongside a high-severity bypass vulnerability. Attackers can exploit these issues to seize full control over vulnerable industrial networking devices. Network administrators must apply the latest firmware updates to prevent potential system compromise.
- Product: Weidmueller Interface (2 products)
- Vulnerabilities: 2 flaws (CVE-2026-63586, CVE-2026-63587)
- Highest severity: 9.8 (Critical · CVSSv3)
- Worst impact: Unauthenticated Remote Code Execution via Shell Injection in Web Management Interface
- Status: No confirmed exploitation yet; patches available
- Action: Update to 1.57, 1.74 now
| CVE | CVSS | Fixed in | Status |
|---|
Why These Vulnerabilities Matter
These flaws present severe risks to industrial control networks that rely on secure communication hardware. The primary vulnerability allows unauthenticated attackers to execute arbitrary commands with root privileges across the operating system. Consequently, malicious actors could deploy persistent backdoors or disrupt essential services entirely. An additional weakness enables remote adversaries to bypass text message authentication protocols. Fortunately, experts have not confirmed any active exploitation in the wild or public proof-of-concept availability.
How the Attacks Work
CVE-2026-63586: OS Command Injection
The web management interface utilizes a modified uhttpd server to process CGI shell scripts. The system extracts the HTTP Basic Authentication username from the Authorization header but fails to sanitize the input. Subsequently, the device inserts this username directly into a shell command string. The security advisory states that a specially crafted username allows attackers to “escape the command context.” They can then “execute arbitrary commands with root privileges” without needing prior authentication.
CVE-2026-63587: Authentication Bypass
The 4G router variants include an SMS control feature that requires a password. However, the system automatically disables this authorization requirement after receiving five invalid password attempts. Remote attackers can intentionally trigger this lockout by repeatedly sending incorrect passwords. Afterward, the router processes all subsequent SMS commands without requiring any credentials.
Affected Versions
These vulnerabilities impact specific Weidmueller hardware models running outdated firmware versions. The affected devices include the IE-SR-2TX-WL and IE-SR-2TX-WL-4G security routers. Specifically, the base wireless model is vulnerable on firmware versions prior to 1.57. Meanwhile, the 4G variants remain vulnerable on firmware releases earlier than 1.74. Exact installation counts remain unavailable, but these routers are common in industrial automation settings.
Patch and Mitigation Steps
Weidmueller strongly urges all users to upgrade their router firmware immediately. Administrators should install firmware version 1.57 for the base model and version 1.74 for the 4G variants. If immediate updates are impossible, restrict web management access using strict firewall rules or a virtual private network. Additionally, disable the SMS control message reception feature on 4G models to block unauthorized text commands.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!