Back

CRITICAL

An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to upload arbitrary firmware through a crafted POST request

Published Sep 29, 2026

Description

An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to upload arbitrary firmware through a crafted POST request. Successful exploitation could allow the attacker to modify device functionality or compromise the integrity or availability of the device.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Hitachi Energy
Published Sep 29, 2026
Updated Sep 29, 2026
Reserved May 7, 2026
CISA Vulnrichment
Updated Sep 29, 2026
NVD
Status Awaiting Analysis
Modified Sep 29, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Hitachi Energy
Published Sep 29, 2026
Updated Sep 29, 2026
Exploited since n/a
EUVD-2026-88666