CVE-2026-67596
CSL 1010 M2M 3G WiFi Module 2.2.1.4 Weak Encryption via Router.cfg
CVSS Score
6.2
EPSS Score
0.0%
EPSS Percentile
0th
CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticated attackers to recover all stored secrets in plaintext by reversing a single-byte XOR cipher with a static key applied to the configuration backup file. Attackers can trivially decrypt the Router.cfg backup file to expose web administration and telnet passwords, WPA/WPA2 pre-shared keys, PPPoE and 3G/APN credentials, and SIM identifiers including IMSI and IMEI.
| CWE | CWE-261 |
| Vendor | csl mobile limited |
| Product | csl 1010 m2m 3g wifi module |
| Published | Jul 30, 2026 |
| Last Updated | Jul 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for csl mobile limited csl 1010 m2m 3g wifi module
Be the first to know when new medium vulnerabilities affecting csl mobile limited csl 1010 m2m 3g wifi module are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
CSL Mobile Limited / CSL 1010 M2M 3G WiFi Module
0 โค 2.2.1.4
References
Credits
Gjoko Krstic of Zero Science Lab