Authentication Bypass in Hitachi Energy RTU500 Firmware Update Endpoint
CVE-2026-8065

9.1CRITICAL

Key Information:

Vendor

Hitachi

Vendor
CVE Published:
29 September 2026

What is CVE-2026-8065?

An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 allows unauthenticated attackers to upload arbitrary firmware via a specially crafted POST request. If exploited, this vulnerability can enable an attacker to alter the functionality of the device, thereby compromising its integrity and availability. Organizations using RTU500 systems should take immediate action to secure their devices against potential exploitation.

Affected Version(s)

RTU500 series CMU firmware 9.0 < 12.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.