← Back to search

CVE-2026-8065

9.1 CRITICAL

Published 2026-09-29 · Updated 2026-09-29

AI risk analysis

Summary
An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-of-life versions allows unauthenticated attackers to upload arbitrary firmware, potentially compromising the device's functionality.
Exploitability
Exploitation is relatively straightforward as it requires crafting a POST request to the firmware update endpoint, which can be automated.
Blast radius
If exploited, the attacker could modify the device's functionality or compromise its integrity and availability, leading to potential operational disruptions.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the firmware update feature or restrict access to the firmware update endpoint.
auth-bypassfirmwareicsunauthenticatedupdate

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to upload arbitrary firmware through a crafted POST request. Successful exploitation could allow the attacker to modify device functionality or compromise the integrity or availability of the device.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Weaknesses

CWE-306

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.