Unauthorized Access Flaw in RTU500 Web Interface by Hitachi Energy
CVE-2026-1772
5.3MEDIUM
What is CVE-2026-1772?
The RTU500 web interface contains a vulnerability that allows an unauthenticated user to access sensitive user management information. While this data cannot be directly viewed through the RTU500 web user interface, it can be retrieved using external tools such as browser development utilities. This flaw could lead to unauthorized information disclosure, potentially compromising user accounts and operational integrity.
Affected Version(s)
RTU500 series CMU firmware 12.7.1 <= 12.7.7
RTU500 series CMU firmware 13.5.1 <= 13.5.4
RTU500 series CMU firmware 13.6.1 <= 13.6.2