← Advisories

CSL 1010 M2M 3G WiFi Module 2.2.1.4 (Router.cfg) Weak XOR Encryption

Medium
Advisory ID
ZSL-2026-6000
Release Date
30 July 2026
Vendor
CSL Mobile Limited - https://1010.com.hk
Affected Version
2.2.1.4
CVE
N/A
Tested On
httpd, Ralink RT5350
Summary

The CSL 1010 M2M 3G WiFi Module is a portable 3G/LTE router that stores its configuration in a backup file (Router.cfg).

Description

The device protects its configuration file (Router.cfg) with a weak/insecure obfuscation (single-byte XOR cipher) using a static key (0xEC) instead of real encryption. Because the same key is applied to the entire file, it is trivially recovered and the configuration can be decoded back to cleartext with a few lines of code. This discloses all stored secrets in plaintext, including the web administration and telnet passwords, the WPA/WPA2 pre-shared key, PPPoE/3G/APN credentials, and SIM identifiers (IMSI/IMEI).

Proof of Concept
Disclosure Timeline
N/A
Credits
Vulnerability discovered by Gjoko Krstic
References
N/A
Changelog
30.07.2026Initial release