CRITICALCVSS 9.11% EPSS
An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to upload arbitrary firmware through a crafted POST request. Successful exploitation could allow the attacker to modify device functionality or compromise the integrity or availability of the device.
Published 2026-09-29 · last modified 2026-09-29
| Vendor | Product |
|---|---|
| hitachi energy | rtu500 series cmu firmware |
Ncerio by BeyondNets · data from NVD, CISA KEV, EPSS.