SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-67596

MEDIUM · CVSS 6.2 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The firmware of the CSL 1010 M2M 3G WiFi Module, up to version 2.2.1.4, contains a weak encryption vulnerability that allows unauthenticated attackers to easily decrypt sensitive configuration files, exposing critical credentials such as web administration passwords and SIM identifiers. This vulnerability poses a medium severity risk, as it enables attackers to gain unauthorized access to network configurations and potentially compromise connected devices. Organizations using this module should prioritize patching or upgrading their firmware to mitigate the risk of credential theft and unauthorized access.

CVE
CVE-2026-67596
Severity
MEDIUM
CVSS
6.2
EPSS
0.11%

Original NVD Description

CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticated attackers to recover all stored secrets in plaintext by reversing a single-byte XOR cipher that uses a static key to obfuscate the configuration backup file. Attackers can trivially decrypt the Router.cfg backup file to expose web administration and telnet passwords, WPA/WPA2 pre-shared keys, PPPoE and 3G/APN credentials, and SIM identifiers including IMSI and IMEI.