CVE-2026-9650 PUBLISHED

Assigner: schneider
Reserved: 26.05.2026 Published: 25.06.2026 Updated: 25.06.2026

CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenticated attacker accesses credentials stored within firmware or system files. With this credential an attacker could subsequently compromise the device if they have physical access to the device.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Schneider Electric
Product EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller
Versions Default: unaffected
  • Version Version 11.06.30 and prior is affected
Vendor Schneider Electric
Product Saitel DP Remote Terminal Unit & Controller
Versions Default: unaffected
  • Version Version 11.06.35 and prior is affected

References

Problem Types

  • CWE-522 Insufficiently Protected Credentials CWE