Unauthorized Access Flaw in RTU500 Web Interface by Hitachi Energy
CVE-2026-1772
5.3MEDIUM
What is CVE-2026-1772?
The RTU500 web interface contains a vulnerability that allows an unauthenticated user to access sensitive user management information. While this data cannot be directly viewed through the RTU500 web user interface, it can be retrieved using external tools such as browser development utilities. This flaw could lead to unauthorized information disclosure, potentially compromising user accounts and operational integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
RTU500 series CMU firmware 12.7.1 <= 12.7.7
RTU500 series CMU firmware 13.5.1 <= 13.5.4
RTU500 series CMU firmware 13.6.1 <= 13.6.2
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved