CVE-2026-8066: Critical severity Hitachi Energy RTU500 vulnerability
A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 allows an unauthenticated attacker to write or overwrite arbitrary files on the device file system. Depending on the files affected, successful exploitation could result in unauthorized modification of device data or disruption of the device’s intended operation.
Other sources
A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to write or overwrite arbitrary files on the device file system. Depending on the files affected, successful exploitation could result in unauthorized modification of device data or disruption of the device’s intended operation.
— NVD
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
No authentication or user interaction is required. The vulnerability is remotely exploitable over the network with low attack complexity.
What is the likely impact if exploitation succeeds?
An attacker can write or overwrite arbitrary files on the RTU500 device file system. This may allow unauthorized modification of device data or disrupt the device’s intended operation.
Is there evidence that confidentiality is affected?
The provided severity vector indicates no confidentiality impact. It indicates high integrity and availability impact.