Vulnerability in Reyrolle 7SR5 Devices from Siemens
CVE-2026-62654
7HIGH
What is CVE-2026-62654?
A vulnerability exists in the Reyrolle 7SR5 protection devices prior to version 2.70, which can be exploited by an attacker with physical access. When activated via a specific key sequence during boot, a maintenance mode triggers the device to download and run program code from a network server without verifying its authenticity or integrity. This flaw presents a significant risk, allowing unauthorized individuals to upload and execute arbitrary, unsigned code, potentially compromising the device's security and functionality.
Affected Version(s)
Reyrolle 7SR5 0