CVE-2026-62649: High severity Reyrolle 7SR5 vulnerability
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The web server does not properly limit or manage system resources when processing a high volume of concurrent HTTP requests. This could allow an unauthenticated remote attacker to cause the entire device to crash and reboot, resulting in a denial-of-service condition.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Reyrolle 7SR5to a version that resolves this vulnerability.Fixed in V2.70
Event History
Frequently Asked Questions
Which deployments are affected?
Reyrolle 7SR5 devices running versions earlier than V2.70 are affected. The issue is in the device web server.
Does exploitation require authentication or user interaction?
No. An unauthenticated remote attacker can exploit the issue, and no user interaction is required.
What is the operational impact of a successful attack?
A high volume of concurrent HTTP requests can cause the entire device to crash and reboot, resulting in denial of service.