๐Ÿ” CVE Alert

CVE-2026-67596

MEDIUM 6.2

CSL 1010 M2M 3G WiFi Module 2.2.1.4 Weak Encryption via Router.cfg

CVSS Score
6.2
EPSS Score
0.0%
EPSS Percentile
0th

CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticated attackers to recover all stored secrets in plaintext by reversing a single-byte XOR cipher with a static key applied to the configuration backup file. Attackers can trivially decrypt the Router.cfg backup file to expose web administration and telnet passwords, WPA/WPA2 pre-shared keys, PPPoE and 3G/APN credentials, and SIM identifiers including IMSI and IMEI.

CWE CWE-261
Vendor csl mobile limited
Product csl 1010 m2m 3g wifi module
Published Jul 30, 2026
Last Updated Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for csl mobile limited csl 1010 m2m 3g wifi module

Be the first to know when new medium vulnerabilities affecting csl mobile limited csl 1010 m2m 3g wifi module are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

CSL Mobile Limited / CSL 1010 M2M 3G WiFi Module
0 โ‰ค 2.2.1.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
zeroscience.mk: https://www.zeroscience.mk/#/advisories/ZSL-2026-6000 1010.com.hk: https://1010.com.hk/ vulncheck.com: https://www.vulncheck.com/advisories/csl-1010-m2m-3g-wifi-module-weak-encryption-via-router-cfg

Credits

Gjoko Krstic of Zero Science Lab