PT-2026-102473 · Hitachi Energy · Rtu500
CVE-2026-8065
·
Published
2026-09-29
·
Updated
2026-09-29
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Hitachi Energy RTU500 versions prior to 2026.2.14
Description
An authentication bypass exists in the firmware update endpoint, allowing an unauthenticated attacker to upload arbitrary firmware via a crafted POST request. This could lead to modified device functionality or a compromise of the device integrity and availability.
Recommendations
Update Hitachi Energy RTU500 to version 2026.2.14 or later.
Fix
RCE
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rtu500