Back to Feed
VulnerabilitiesOct 6, 2026

Hitachi Energy RTU500

Hitachi Energy RTU500 firmware versions <=11.x affected by multiple critical vulnerabilities.

Summary

Hitachi Energy has issued a cybersecurity advisory detailing multiple vulnerabilities in end-of-life RTU500 CMU firmware versions 11.x and prior. These vulnerabilities, reported by Dragos, include authentication bypass, directory traversal, and improper authorization, with CVSS scores up to 9.8. Exploitation could lead to device compromise, data modification, or service disruption. Hitachi Energy strongly recommends upgrading to supported firmware versions.

Full text

ICS Advisory Hitachi Energy RTU500 Release DateOctober 06, 2026 Alert CodeICSA-26-279-06 Related topics: Industrial Control System Vulnerabilities , Industrial Control Systems View CSAF Summary Hitachi Energy is publishing this cybersecurity advisory in response to the security findings reported by Dragos affecting end-of-life RTU500 CMU firmware version 9.x. The reported findings are associated with legacy RTU500 firmware versions that were developed according to the cybersecurity requirements, threat landscape, and industry practices that existed at the time of their release. As cybersecurity threats and security expectations have evolved, these end-of-life versions no longer incorporate many of the security controls and hardening measures that are standard in modern industrial control systems. Over successive RTU500 releases, Hitachi Energy has continuously enhanced the security of the product through the introduction of additional security features, protocol hardening, stronger authentication and access controls, encrypted communications, and other security-by-design improvements. While the findings reported by Dragos do not affect currently supported RTU500 CMU firmware versions, there is a likelihood that the end-of-life versions 11.x and prior are affected by these vulnerabilities. Since the end-of-life versions are no longer maintained with security updates, Hitachi Energy strongly recommends upgrading to a currently supported RTU500 firmware version. Customers should also implement appropriate defense-in-depth measures and cybersecurity best practices to reduce risk and strengthen the security posture of their operational environments. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The following versions of Hitachi Energy RTU500 are affected: RTU500 series CMU Firmware vers:RTU500_series_CMU_Firmware/<=11.x (CVE-2026-8065, CVE-2026-8066, CVE-2026-8067, CVE-2010-2965, CVE-2014-9195, CVE-2023-46143) CVSS Vendor Equipment v3 9.8 Hitachi Energy RTU500 series CMU Firmware 5 Vulnerabilities Missing Authentication for Critical Function, Relative Path Traversal, Missing Authorization, Incorrect Authorization, Download of Code Without Integrity Check Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2026-8065 An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 allows an unauthenticated attacker to upload arbitrary firmware through a crafted POST request. Successful exploitation could allow the attacker to modify device functionality or compromise the integrity or availability of the device. Read More 1 Affected Product RTU500 series CMU Firmware versions 11.x and prior (End-of-Life) Product Status: known_affected Remediations Vendor fixUpgrade to version 12.7.8 or 13.9.1 or latest Additional Metrics Relevant CWE: CWE-306 Missing Authentication for Critical Function CVSS Version Base Score Base Severity Vector String 3.1 9.1 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H View CVE Details CVE-2026-8066 A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 allows an unauthenticated attacker to write or overwrite arbitrary files on the device file system. Depending on the files affected, successful exploitation could result in unauthorized modification of device data or disruption of the device’s intended operation. Read More 2 Affected Products RTU500 series CMU Firmware versions 11.x and prior (End-of-Life) Product Status: known_affected Remediations Vendor fixUpgrade to version 12.7.8 or 13.9.1 or latest RTU500 series CMU Firmware versions 11.x and prior (End-of-Life) Product Status: known_affected Remediations Vendor fixUpgrade to version 12.7.8 or 13.9.1 or latest Additional Metrics Relevant CWE: CWE-23 Relative Path Traversal CVSS Version Base Score Base Severity Vector String 3.1 9.1 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H View CVE Details CVE-2026-8067 An improper authorization vulnerability in the RTU500’s web application allows an authenticated user to trigger the RTU500 to reboot through the reset endpoint. Successful exploitation could cause temporary device unavailability and disruption of its intended operation. Read More 3 Affected Products RTU500 series CMU Firmware versions 11.x and prior (End-of-Life) Product Status: known_affected Remediations Vendor fixUpgrade to version 12.7.8 or 13.9.1 or latest RTU500 series CMU Firmware versions 11.x and prior (End-of-Life) Product Status: known_affected Remediations Vendor fixUpgrade to version 12.7.8 or 13.9.1 or latest RTU500 series CMU Firmware versions 11.x and prior (End-of-Life) Product Status: known_affected Remediations Vendor fixUpgrade to version 12.7.8 or 13.9.1 or latest Additional Metrics Relevant CWE: CWE-862 Missing Authorization CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H View CVE Details CVE-2010-2965 The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on few of the Hitachi Energy RTU500 CMU firmware legacy versions, allows remote attackers to read or modify arbitrary memory locations, perform function calls, or manage tasks via requests to UDP port 17185. Read More 4 Affected Products RTU500 series CMU Firmware versions 11.x and prior (End-of-Life) Product Status: known_affected Remediations Vendor fixUpgrade to version 12.7.8 or 13.9.1 or latest RTU500 series CMU Firmware versions 11.x and prior (End-of-Life) Product Status: known_affected Remediations Vendor fixUpgrade to version 12.7.8 or 13.9.1 or latest RTU500 series CMU Firmware versions 11.x and prior (End-of-Life) Product Status: known_affected Remediations Vendor fixUpgrade to version 12.7.8 or 13.9.1 or latest RTU500 series CMU Firmware versions 11.x and prior (End-of-Life) Product Status: known_affected Remediations Vendor fixUpgrade to version 12.7.8 or 13.9.1 or latest Additional Metrics Relevant CWE: CWE-863 Incorrect Authorization CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H View CVE Details CVE-2014-9195 Missing authentication vulnerability in a network service of Hitachi Energy RTU500 allows an unauthenticated remote attacker to execute arbitrary commands using protocol-compliant network traffic. Successful exploitation could result in unauthorized modification of the device or disruption of its intended operation. Read More 5 Affected Products RTU500 series CMU Firmware versions 11.x and prior (End-of-Life) Product Status: known_affected Remediations Vendor fixUpgrade to version 12.7.8 or 13.9.1 or latest RTU500 series CMU Firmware versions 11.x and prior (End-of-Life) Product Status: known_affected Remediations Vendor fixUpgrade to version 12.7.8 or 13.9.1 or latest RTU500 series CMU Firmware versions 11.x and prior (End-of-Life) Product Status: known_affected Remediations Vendor fixUpgrade to version 12.7.8 or 13.9.1 or latest RTU500 series CMU Firmware versions 11.x and prior (End-of-Life) Product Status: known_affected Remediations Vendor fixUpgrade to version 12.7.8 or 13.9.1 or latest RTU500 series CMU Firmware versions 11.x and prior (End-of-Life) Product Status: known_affected Remediations Vendor fixUpgrade to version 12.7.8 or 13.9.1 or latest Additional Metrics Relevant CWE: CWE-306 Missing Authentication for Critical Function CVSS Version Base Score Base Severity Vector String 3.1 8.1 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H View CVE Details CVE-2023-46143 A download of code without integrity check vulnerability in Hitachi Energy RTU500 allows an unauthenticated remote attacker to modify some or all applications running on the device. Successful exploitation could result in unauthorized modification of device functionality or disruption of its intended o

Indicators of Compromise

  • cve — CVE-2026-8065
  • cve — CVE-2026-8066
  • cve — CVE-2026-8067
  • cve — CVE-2010-2965
  • cve — CVE-2014-9195
  • cve — CVE-2023-46143

Entities

RTU500 CMU Firmware (product)Hitachi Energy (vendor)Dragos (threat_actor)Industrial Control Systems (technology)