Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 29 Sep 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to upload arbitrary firmware through a crafted POST request. Successful exploitation could allow the attacker to modify device functionality or compromise the integrity or availability of the device. | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Hitachi Energy
Published:
Updated: 2026-09-29T15:54:11.550Z
Reserved: 2026-05-07T05:51:56.353Z
Link: CVE-2026-8065
No data.
Status : Received
Published: 2026-09-29T10:17:13.110
Modified: 2026-09-29T16:17:14.187
Link: CVE-2026-8065
No data.
OpenCVE Enrichment
No data.