Vulnerability in Reyrolle 7SR5 Devices from Siemens
CVE-2026-62654

7HIGH

Key Information:

Vendor

Siemens

Vendor
CVE Published:
8 September 2026

What is CVE-2026-62654?

A vulnerability exists in the Reyrolle 7SR5 protection devices prior to version 2.70, which can be exploited by an attacker with physical access. When activated via a specific key sequence during boot, a maintenance mode triggers the device to download and run program code from a network server without verifying its authenticity or integrity. This flaw presents a significant risk, allowing unauthorized individuals to upload and execute arbitrary, unsigned code, potentially compromising the device's security and functionality.

Affected Version(s)

Reyrolle 7SR5 0

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.