The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliberately trigger this by submitting 5 or more invalid passwords, after which subsequent SMS commands are executed without requiring a password, resulting in potential limited configuration tampering, limited information leakage and potentially full loss of availability.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-63587 affects IE-SR-2TX-WL-4G industrial devices by exploiting a critical design flaw in SMS command authentication. When the 'Enable Password Authorization' setting is enabled, the device is supposed to protect SMS commands with password verification. However, the implementation contains a dangerous logic error: after just 5 consecutive failed password attempts, the device automatically disables SMS password authorization entirely, allowing any subsequent SMS commands to execute without authentication. An unauthenticated attacker with SMS access to the device can intentionally trigger five failed attempts to permanently bypass this security control, gaining unauthorized command execution on critical industrial infrastructure. This is particularly dangerous because SMS is often considered a legacy but trusted channel in industrial environments, and devices may be remotely deployed where physical intervention isn't feasible.
While this CVE maps to CWE-288 (Authentication Bypass by Alternate Route), it does not currently align with specific MITRE ATT&CK techniques in the standard framework—indicating a gap in how industrial IoT authentication failures are captured in adversarial models. Casky practitioners would detect attack patterns through behavioral analysis of SMS command submissions: a spike in failed authentication attempts followed by successful command execution without credentials would trigger anomalous activity detection. Extended reasoning across Casky's 754 security skills would identify this as an authentication state-change attack, correlating failed SMS attempts with subsequent privileged operations. Practitioners should look for indicator patterns including: multiple SMS password rejections from external numbers, followed by command execution that bypasses normal authorization logs, and timing patterns consistent with intentional retry exhaustion rather than user error.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-63587. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation