CVE-2026-8066
9.1 CRITICALPublished 2026-09-29 · Updated 2026-09-29
AI risk analysis
- Summary
- A directory traversal vulnerability allows unauthenticated attackers to write or overwrite arbitrary files on the device, potentially disrupting the device’s operation or modifying its data.
- Exploitability
- Exploitation is relatively straightforward as it requires no authentication, but the attacker must know the specific file paths to target.
- Blast radius
- If exploited, the vulnerability could lead to unauthorized modification of critical device data or disruption of the device’s intended operation.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Disable the file upload functionality or restrict access to the affected feature.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to write or overwrite arbitrary files on the device file system. Depending on the files affected, successful exploitation could result in unauthorized modification of device data or disruption of the device’s intended operation.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Weaknesses
CWE-23
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-8065
- HIGHCVE-2026-18907
- CRITICALCVE-2023-54400PoC
- CRITICALCVE-2026-103040PoC
- CRITICALCVE-2026-103041PoC
- HIGHCVE-2026-13248
- CRITICALCVE-2026-13249
- HIGHCVE-2026-15027
Related by shared AI tags and CWE weakness class. Browse the full archive.