PT-2026-102473 · Hitachi Energy · Rtu500

CVE-2026-8065

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hitachi Energy RTU500 versions prior to 2026.2.14
Description An authentication bypass exists in the firmware update endpoint, allowing an unauthenticated attacker to upload arbitrary firmware via a crafted POST request. This could lead to modified device functionality or a compromise of the device integrity and availability.
Recommendations Update Hitachi Energy RTU500 to version 2026.2.14 or later.

Fix

RCE

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8065

Affected Products

Rtu500