CVE-2026-1772: Medium severity hitachienergy Rtu520 Firmware vulnerability
RTU500 web interface: An unprivileged user can read user management information. The information cannot be accessed via the RTU500 web user interface but requires further tools like browser development utilities to access them without required privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1772?
The severity of CVE-2026-1772 has been classified as moderate due to the ability of an unprivileged user to access sensitive user management information.
How do I fix CVE-2026-1772?
To fix CVE-2026-1772, apply the latest firmware updates provided by Hitachi Energy for affected RTU520, RTU530, RTU540, and RTU560 devices.
What systems are affected by CVE-2026-1772?
CVE-2026-1772 affects specific versions of Hitachi Energy RTU520, RTU530, RTU540, and RTU560 firmware ranging from 12.7.1 to 13.8.1.
Can an attacker exploit CVE-2026-1772 remotely?
CVE-2026-1772 requires physical access or specialized tools to exploit, as the information is not publicly accessible via the RTU500 web interface.
What are the implications of CVE-2026-1772 for my organization?
Organizations using vulnerable versions may unintentionally expose sensitive user management information, which could lead to unauthorized access or operational issues.