- The Mess: Weidmueller’s IE-SR-2TX-WL and IE-SR-2TX-WL-4G industrial security routers have multiple vulnerabilities, including CVE-2026-63586, a critical unauthenticated remote code execution flaw. The bug can let an attacker execute arbitrary commands with root privileges on the router.
This is not some harmless web-interface glitch. These devices sit in industrial networks, where a compromised router can become a very convenient bridge into systems that were never supposed to be directly exposed.
And there is more. The affected IE-SR-2TX-WL-4G model also has CVE-2026-63587, an SMS password authorization bypass. In other words, the security router has problems with both remote command execution and authentication logic. Excellent combination.
- The Damage: A root-level compromise of an industrial router can expose network traffic, alter routing, provide persistence, and give an attacker a foothold for moving deeper into an OT environment.
The danger is bigger than the router itself.
Industrial networks often contain PLCs, SCADA systems, engineering workstations and other equipment where “just reboot it” is not a realistic incident-response strategy. A compromised edge device can also be abused to hide subsequent attacks behind infrastructure that the organization already trusts.
This is why CVSS 9.8 matters here. The vulnerable device is part of the network’s defensive perimeter, not someone’s forgotten home Wi-Fi box.
- The Fix: Update affected Weidmueller routers to the vendor-provided fixed firmware immediately, restrict management access from untrusted networks, and inspect logs and configurations for unauthorized changes; Weidmueller’s security advisory confirms that fixes are available.
Bugstoday Opinion
An industrial security router that can be remotely pushed into root-level command execution is exactly the kind of device nobody wants sitting on the public internet.
And yet they do.
The annoying part is predictable: the router exists to protect the network, but a remotely exploitable flaw turns that same box into an attacker’s network access point.
Bugstoday verdict: if these routers are exposed, stop treating this as a firmware update. Treat it as a security incident until you prove otherwise.



