Improper Authorization in RTU500 Web Application from Hitachi Energy
CVE-2026-8067

6.5MEDIUM

Key Information:

Vendor

Hitachi

Vendor
CVE Published:
29 September 2026

What is CVE-2026-8067?

An improper authorization issue in the RTU500's web application enables authenticated users to exploit the reset endpoint, allowing them to initiate a reboot of the device. This can lead to temporary unavailability and disrupt the normal operations of the RTU500, affecting system performance and reliability.

Affected Version(s)

RTU500 series CMU firmware 9.0 < 12.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.