CyberRota Analysis
AI-GeneratedThe SMS control function in IE-SR-2TX-WL-4G devices is vulnerable due to a flaw in the password authorization mechanism, allowing an unauthenticated remote attacker to disable SMS password protection by sending five consecutive invalid password attempts. This exploitation can lead to unauthorized execution of SMS commands, resulting in limited configuration tampering, information leakage, and potential denial of service. Organizations using these devices should prioritize patching this vulnerability to safeguard against potential attacks.
Original NVD Description
The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliberately trigger this by submitting 5 or more invalid passwords, after which subsequent SMS commands are executed without requiring a password, resulting in potential limited configuration tampering, limited information leakage and potentially full loss of availability.