← Back to search

CVE-2026-8066

9.1 CRITICAL

Published 2026-09-29 · Updated 2026-09-29

AI risk analysis

Summary
A directory traversal vulnerability allows unauthenticated attackers to write or overwrite arbitrary files on the device, potentially disrupting the device’s operation or modifying its data.
Exploitability
Exploitation is relatively straightforward as it requires no authentication, but the attacker must know the specific file paths to target.
Blast radius
If exploited, the vulnerability could lead to unauthorized modification of critical device data or disruption of the device’s intended operation.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the file upload functionality or restrict access to the affected feature.
directory-traversalicsfile-overwriteunauthenticateddevice-disruption

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to write or overwrite arbitrary files on the device file system. Depending on the files affected, successful exploitation could result in unauthorized modification of device data or disruption of the device’s intended operation.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Weaknesses

CWE-23

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.