CVE-2026-62652: Medium severity Reyrolle 7SR5 vulnerability
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The device firmware contains binaries from which debugging symbols have not been removed. This could allow an unauthenticated attacker with access to the publicly available firmware update files to more easily reverse engineer the device's firmware, facilitating the identification of further vulnerabilities.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Reyrolle 7SR5to a version that resolves this vulnerability.Fixed in V2.70
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
An attacker needs access to the publicly available firmware update files. No authentication, user interaction, or direct access to a deployed device is described as necessary for obtaining the debugging symbols.
Are deployed devices directly compromised by this vulnerability?
The described impact is that retained debugging symbols make firmware reverse engineering easier and may help identify further vulnerabilities. The available information does not describe direct code execution, configuration modification, or service disruption on a device from this issue alone.
Which versions are affected?
All Reyrolle 7SR5 versions earlier than V2.70 are affected. The provided information does not state whether V2.70 or later versions are affected.