Skip to content
Critical Authentication Bypass in Hitachi Energy RTU500 Firmware

Critical Authentication Bypass in Hitachi Energy RTU500 Firmware

First seen 29 Sep 2026, 15:41 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 16:22 UTC
  • •CVE-2026-8065 allows unauthenticated firmware uploads to Hitachi Energy RTU500.
  • •The vulnerability has a CVSS score of 9.1, marking it as critical.
  • •Affected firmware versions include 9.0 and 12.0; testing should be done in isolated environments only.

On September 29, 2026, Hitachi Energy disclosed CVE-2026-8065, a critical authentication bypass vulnerability in the RTU500 Series CMU firmware update endpoint. This flaw allows unauthenticated attackers to upload arbitrary firmware, compromising the integrity and availability of the Remote Terminal Unit (RTU). The vulnerability has a CVSS score of 9.1, indicating its critical nature, particularly in operational technology (OT) environments. The affected firmware versions include 9.0 and 12.0, with advisories recommending testing only in isolated environments. The exploit involves sending crafted POST requests to the firmware update endpoint without authentication. Public advisories may not yet detail the exact URI for the vulnerability, and testing should be conducted only in controlled settings. The vendor has advised that the exploit should not be directed at live grid equipment without proper isolation and coordination.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2024-04-30
CVE-2024-2617 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-20
CVE-2026-93958 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-24
CVE-2026-13249 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-29
CVE-2026-8065 published
Hitachi Energy disclosed a critical authentication bypass vulnerability in RTU500 firmware, allowing arbitrary firmware uploads.
Sploitus

More articles in this cluster (4)

Following this threat?

Track Hitachi Energy and CVE-2024-2617 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed