Python 3 PoC for **[CVE-2026-8065]( — **Hitachi Energy** **RTU500 Series CMU Firmware** — **authentication bypass (CWE-306)** on the **firmware update** HTTP endpoint. **CVSS 3.1 9.1 Critical** (IoT/OT).
| **PoCbit** | |
| **NVD** | |
| **Vector** | `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H` |
| **CWE** | CWE-306 Missing Authentication for Critical Function |
| **Impact** | Unauthenticated **arbitrary firmware upload** → integrity / availability of substation RTU |
**RTU500**, enerji iletim/dağıtım sahasında kullanılan **Remote Terminal Unit** (uzak terminal) ailesidir; web sunucusu üzerinden **CMU firmware** yönetimi yapılır. **CVE-2026-8065**’te, **firmware güncelleme** uç noktası **kimlik doğrulaması olmadan** (veya **craft edilmiş POST** ile bypass) erişilebilir hale gelir; saldırgan **keyfi firmware** yükleyerek cihaz işlevini değiştirebilir, bütünlüğü bozabilir veya **DoS** oluşturabilir.
Bu, otomasyon ağında **PR:N** ile uzaktan kritik OT etkisi anlamına gelir — yalnızca **yetkili izolasyon laboratuvarında** veya **vendor onaylı pentest** kapsamında test edilmelidir.
**Vendor (CNA) etkilenen:** RTU500 Series CMU Firmware — **9.0** ve **12.0** sürüm hatları (custom versioning; güncel advisory ve **13.8.2+** patch notlarına bakın).
Hitachi Energy assigned **CVE-2026-8065** (published 2026-09-29):
> An authentication bypass vulnerability in the **firmware update endpoint** of Hitachi Energy RTU500 allows an **unauthenticated** attacker to upload **arbitrary firmware** through a **crafted POST** request.
Unlike **CVE-2024-2617** (authenticated user bypassing *secure update* when disabled), **CVE-2026-8065** is **unauthenticated** access to the update function itself — a full **CWE-306** gap on a safety-critical OT surface.
Public advisories may not yet list the exact URI; RTU500 documentation describes firmware handling via **Configuration Management** / web server file transfer. This PoC **fingerprints** RTU500 and **probes** a curated list of likely firmware POST paths, then (exploit mode) sends a **non-production probe blob** (`POCBIT-8065-FW-PROBE`) to detect **unauthenticated accept** responses.
| **check** | Multi-port HTTP(S) probe, RTU500 HTML markers, CMU version regex, **GET** probe on firmware paths |
| **exploit** | **POST** multipart fake `.fw` without session cookie; **`exploited`** if 2xx + accept heuristics |
| **mass** | `--list` + `-j`; `hits.txt` / **`exploited.txt`** |
| **`--dry-run`** | Exploit: GET firmware path probe only (no POST) |
| **`--lab`** | Local mock RTU500 — must show `exploited: true` (sanity check) |
| **`--force`** | Exploit without RTU500 HTML fingerprint |
| **`--firmware-paths`** | Override path list (comma-separated) when vendor path is known |
JSONL: `pocbit`, `pocbit_catalog`, `pocbit_page`, `cve`, `vendor`, `product`.
**Safety:** Default exploit payload is **not** a valid CMU flash image — only a **marker + padding** for detection. **Never** point exploit mode at live grid equipment without isolation and vendor coordination.
python poc.py -u --mode check
python poc.py -u --mode exploit --dry-run
python poc.py -u --mode exploit
python poc.py -u --mode exploit --firmware-paths /api/firmware/update
`--list --mode check` ile **bulk varsayılan açık**: hedef başına 1–2 GET (liste URL’si + gerekirse http/https), **16 firmware path taraması yok**, kısa timeout `(4s connect, 10s read)`, varsayılan `-j 32`.
python poc.py --list fofa_targets_rtu_priority.txt --mode check -j 40
python poc.py --list fofa_csv_1000.csv --mode check -j 50 --timeout 8
python poc.py --list targets.txt --mode check --full -j 20 # yavaş: çoklu port + tüm firmware GET
python poc.py --list hits.txt --mode exploit -j 8 --timeout 25
CLI’da ilerleme: `[done/total hedef/s]`; hit’ler anında `HIT` olarak yazılır.
`cert="Hitachi"` FOFA listesi çok gürültülüdür; CSV’de **`rtu_priority`** ile önce priority listeyi tarayın. **Check hit ≠ gerçek RTU:** sayfada sadece `hitachi energy` geçen kurumsal SPA’lar **`vendor_branding_only`** / **`vendor_branding_spa_false_positive`** olur; exploit için **`rtu500` / `rtutil500` / `cmu firmware`** gibi **strong** fingerprint gerekir (yoksa `--force`).
python poc.py --list fofa_targets_rtu_priority.txt --mode check --full -j 20
python poc.py --list hits.txt --mode exploit --dry-run -j 8
- `/api/firmware/update`, `/api/firmware/upload`, `/api/v1/firmware/update`
- `/firmware/update`, `/firmware/upload`, `/ws/firmware/update`
- `/CMU/firmware/upload`, `/ConfigurationManagement/Firmware`
- `/configuration/management/firmware`, `/FileUpload/Firmware`
- `/scripts/firmwareUpload`, `/cgi-bin/firmware`, `/admin/firmware/upload`
When Hitachi publishes the exact path, set **`--firmware-paths`** to that URI only.
title="RTU500" || body="RTU500" || body="Configuration Management"
body="Hitachi Energy" && (body="RTU" || body="CMU")
OT ağlarında FOFA eksik olabilir; **CMMS / IP planı / VPN jump** envanterini `targets.txt` yapın.
1. Apply **Hitachi Energy** security advisory / **CMU firmware** per [publisher.hitachienergy.com]( (CVE reference **CVE-2026-8065**).
2. **Network segmentation** — RTU web arayüzünü internete açmayın; jump host + MFA.
3. **Monitor** anormal firmware POST / configuration changes.
4. **IEC 62351-3** and secure update policies (see also CVE-2024-2617 secure-update hardening).
- [PoCbit CVE-2026-8065](
- [CVE.report CVE-2026-8065](
- [NVD CVE-2026-8065](
- CISA ICS advisories for RTU500 (related CVEs: IEC104 DoS, web info disclosure)
- Hitachi Energy RTU500 product / web server manuals (Configuration Management, firmware file handling)
**Authorized** substation/lab testing only. Unauthorized firmware manipulation on OT devices may violate law and grid safety rules.
CVE-2026-8065 PoC: Hitachi Energy RTU500 unauth firmware update bypass (CWE-306, CVSS 9.1). IoT/OT colored check + mass exploit — RTU500 fingerprint, firmware endpoint probe, lab-safe upload test.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
