WEIDMUELLER: WLAN devices affected by Hard-coded Credentials vulnerability
Description
In Weidmueller Industrial WLAN devices in multiple versions the usage of hard-coded cryptographic keys within the service agent binary allows for the decryption of captured traffic across the network from or to the device.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Hard-coded cryptographic keys in Weidmueller Industrial WLAN devices allow network attackers to decrypt captured traffic.
Vulnerability
In Weidmueller Industrial WLAN devices across multiple versions, the service agent binary contains hard-coded cryptographic keys [1]. This allows an attacker to decrypt traffic captured from or to the device without any special configuration requirements.
Exploitation
An attacker with network access to the device's communication can capture encrypted network traffic. Using the hard-coded keys extracted from the binary, the attacker can decrypt the captured traffic to obtain plaintext data [1]. No authentication or user interaction is required.
Impact
Successful exploitation results in complete loss of confidentiality for all network traffic between the device and other hosts. The attacker can read sensitive information such as credentials, control commands, or industrial process data [1].
Mitigation
No mitigation details are provided in the available reference [1]. Users should contact Weidmueller for updated firmware or consider network segmentation to limit exposure until a fix is available.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Weidmüller/IE-WL(T)-BL-AP-CL-XXv5Range: IE-WL-BL-AP-CL-EU (2536600000)
- Weidmüller/IE-WL(T)-VL-AP-CL-XXv5Range: IE-WL-VL-AP-BR-CL-EU (2536680000)
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- cert.vde.com/en-us/advisories/vde-2021-026mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.