CVE-2026-8065 PUBLISHED

Assigner: Hitachi Energy
Reserved: 07.05.2026 Published: 29.09.2026 Updated: 29.09.2026

An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to upload arbitrary firmware through a crafted POST request. Successful exploitation could allow the attacker to modify device functionality or compromise the integrity or availability of the device.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CVSS Score: 9.1

Product Status

Vendor Hitachi Energy
Product RTU500 series CMU firmware
Versions Default: unaffected
  • affected from 9.0 to 12.0 (excl.)

References

Problem Types

  • CWE-306 Missing authentication for critical function CWE

Impacts

  • CAPEC-638 Altered Component Firmware