CVE-2026-62653: Medium severity Reyrolle 7SR5 vulnerability
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The input received over a proprietary communication protocol that is exposed when the device is placed into a special firmware-update mode is not properly validated, resulting in a memory corruption condition. This could allow an unauthenticated attacker with physical access to the device to cause a crash and potentially execute arbitrary code on the device.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Reyrolle 7SR5to a version that resolves this vulnerability.Fixed in V2.70
Event History
Frequently Asked Questions
Which devices are affected?
Reyrolle 7SR5 devices running versions earlier than V2.70 are affected.
What access does an attacker need?
Exploitation requires physical access to the device. The attacker does not need to authenticate, but the device must be placed into its special firmware-update mode so the proprietary communication protocol is exposed.
What could exploitation allow?
An attacker could trigger a memory corruption condition, causing the device to crash. The issue could also potentially allow arbitrary code execution on the device.