CVE-2026-8065: Critical severity Hitachi Energy RTU500 vulnerability
An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 allows an unauthenticated attacker to upload arbitrary firmware through a crafted POST request. Successful exploitation could allow the attacker to modify device functionality or compromise the integrity or availability of the device.
Other sources
An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to upload arbitrary firmware through a crafted POST request. Successful exploitation could allow the attacker to modify device functionality or compromise the integrity or availability of the device.
— NVD
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The vulnerability can be exploited remotely over the network with no authentication, no user interaction, and low attack complexity. An attacker uses a crafted POST request to the firmware update endpoint.
What could an attacker do after successful exploitation?
An attacker can upload arbitrary firmware to the affected device. This could modify device functionality or compromise the device's integrity or availability.