CVE-2026-8065

CRITICALCVSS 9.11% EPSS

An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to upload arbitrary firmware through a crafted POST request. Successful exploitation could allow the attacker to modify device functionality or compromise the integrity or availability of the device.

Published 2026-09-29 · last modified 2026-09-29

Affected products

VendorProduct
hitachi energyrtu500 series cmu firmware

Full record at NVD ↗

← Get alerted the moment a CVE hits your gear — subscribe free

Ncerio by BeyondNets · data from NVD, CISA KEV, EPSS.