{"id":"CVE-2026-8066","published":"2026-09-29T10:17:13.250","lastModified":"2026-09-29T21:39:02.570","description":"A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to write or overwrite arbitrary files on the device file system. Depending on the files affected, successful exploitation could result in unauthorized modification of device data or disruption of the device’s intended operation.","cvssScore":9.1,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","cwes":["CWE-23"],"vendors":[],"products":[],"references":[{"url":"https://publisher.hitachienergy.com/preview?DocumentID=8DBD000251&LanguageCode=en&DocumentPartId=&Action=Launch","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"A directory traversal vulnerability allows unauthenticated attackers to write or overwrite arbitrary files on the device, potentially disrupting the device’s operation or modifying its data.","exploitability":"Exploitation is relatively straightforward as it requires no authentication, but the attacker must know the specific file paths to target.","blast_radius":"If exploited, the vulnerability could lead to unauthorized modification of critical device data or disruption of the device’s intended operation.","remediation":"Disable the file upload functionality or restrict access to the affected feature.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["directory-traversal","ics","file-overwrite","unauthenticated","device-disruption"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T08:58:07.094Z"}}