PatchSiren

Weidmueller Interface CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Weidmueller Interface CVE published 2026-08-25

CVE-2026-63587

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T09:17:32.057Z and has not been modified since then. The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. An unauthenticated remote attacker can deliberately trigger a retry counter by submitting 5 or more inva [truncated]

CRITICAL Weidmueller Interface CVE published 2026-08-25

CVE-2026-63586

The CVE record for CVE-2026-63586 was published on 2026-08-25T09:17:31.823Z and has not been modified since then. This vulnerability affects a web-based management interface with a modified uhttpd server and CGI shell scripts. The vulnerability class is related to command injection via shell metacharacters in the HTTP Basic Authentication username. The likely operational impact is critical, with potential [truncated]