CVE-2026-67596
CVE-2026-67596 is a medium-severity vulnerability with a CVSS 3.x base score of 6.2. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-261.
Key facts
- Severity: Medium (CVSS 3.x base score 6.2)
- CVSS v4: 6.9
- EPSS exploit prediction: 0% (1st percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-261
- Published:
- Last modified:
Description
CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticated attackers to recover all stored secrets in plaintext by reversing a single-byte XOR cipher that uses a static key to obfuscate the configuration backup file. Attackers can trivially decrypt the Router.cfg backup file to expose web administration and telnet passwords, WPA/WPA2 pre-shared keys, PPPoE and 3G/APN credentials, and SIM identifiers including IMSI and IMEI.
Frequently asked questions
- What is CVE-2026-67596?
- CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticated attackers to recover all stored secrets in plaintext by reversing a single-byte XOR cipher that uses a static key to obfuscate the configuration backup file. Attackers can trivially decrypt the Router.cfg backup file to expose web administration and telnet passwords, WPA/WPA2 pre-shared keys, PPPoE and 3G/APN credentials, and SIM identifiers including IMSI and IMEI.
- How severe is CVE-2026-67596?
- CVE-2026-67596 has a CVSS 3.x base score of 6.2, rated medium severity. It is exploitable over local access with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2026-67596 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (1st percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-67596?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-67596 published?
- CVE-2026-67596 was published on 2026-07-30 and last updated on 2026-07-31.
References
- https://1010.com.hk/
- https://www.vulncheck.com/advisories/csl-1010-m2m-3g-wifi-module-weak-encryption-via-router-cfg
- https://www.zeroscience.mk/#/advisories/ZSL-2026-6000
Other CWE-261 vulnerabilities
- CVE-2025-31229 — Critical (CVSS 9.1): A logic issue was addressed with improved checks. This issue is fixed in iOS 18.6 and iPadOS 18.6. Passcode may be read…
- CVE-2024-24279 — High (CVSS 8.8): An issue in secdiskapp 1.5.1 (management program for NewQ Fingerprint Encryption Super Speed Flash Disk) allows…
- CVE-2024-7407 — High (CVSS 8.2): Use of a custom password encoding algorithm in Streamsoft Prestiż software allows straightforward decoding of…
- CVE-2024-28270 — High (CVSS 8.1): An issue discovered in web-flash v3.0 allows attackers to reset passwords for arbitrary users via crafted POST request…
- CVE-2025-2862 — High (CVSS 7.5): SaTECH BCU, in its firmware version 2.1.3, performs weak password encryption. This allows an attacker with access to…
- CVE-2026-63424 — High (CVSS 7.3): During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could…