Sceawere

Vulnerability Detail

CVE-2026-62650UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Reyrolle 7SR5 RBAC Bypass

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
3h ago
Vendor
Siemens
Product
Reyrolle 7SR5
Attack Type
CWE-288: Authentication Bypass Using an Alternate Path or Channel
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Server-side authorization checks in the web-based management interface are not properly enforced, allowing role-based access control (RBAC) restrictions to be bypassed through manipulation of request data. This could allow an authenticated, low-privileged remote attacker to escalate privileges to an administrative level.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-09-08T09:18:17.213Z",
  "pubdate": "2026-09-08T09:18:17.213Z",
  "executiveSummary": "A critical server-side authorization vulnerability exists in the web-based management interface of Reyrolle 7SR5 devices (all versions prior to V2.70).\nThe flaw stems from insufficient enforcement of role-based access control (RBAC) mechanisms within the server-side logic.\nThis vulnerability allows an authenticated, low-privileged remote attacker to bypass intended security restrictions and escalate privileges to an administrative level.\nSuccessful exploitation grants the attacker full administrative control over the affected device, potentially leading to unauthorized system configuration changes or complete device compromise.\nThe vulnerability requires the attacker to be authenticated to the web management interface; however, no further interaction is required to elevate privileges beyond the initial low-level access.\nThe risk is significant due to the critical nature of industrial protection relays, where unauthorized access can disrupt operational technology environments.",
  "technicalDetails": "The vulnerability is classified as an improper authorization flaw within the server-side logic of the Reyrolle 7SR5 web-based management interface.\nThe root cause is the failure of the application to consistently validate the user's role and associated permissions when processing requests that modify device states or configurations.\nSpecifically, the server-side implementation trusts request parameters without sufficient re-validation against the authenticated user's session role during sensitive operations.\nAn authenticated low-privileged attacker can exploit this by intercepting and manipulating HTTP requests directed at the management interface.\nBy modifying specific parameters or headers within the request body or URL path, an attacker can coerce the backend application into performing administrative actions intended for higher-privileged accounts.\nThe attack flow follows a structured path: first, the attacker authenticates as a standard user with restricted access permissions; second, the attacker identifies a sensitive request destined for the management API; third, the attacker injects or alters request data to circumvent internal role checks; finally, the server processes the request with elevated privilege, applying changes as an administrator.\nThis bypass effectively renders the RBAC model non-functional for those operations, allowing for unauthorized escalation of privileges.\nThe vulnerable component is the server-side logic governing the web-based management interface. The scope of impact includes all Reyrolle 7SR5 versions earlier than V2.70.\nBecause the interface is web-based, the device is susceptible if reachable via the network. Successful exploitation results in complete administrative compromise, allowing an attacker to modify protection settings, access sensitive logs, or potentially disrupt the device's primary relay functions.\nThe lack of robust server-side enforcement ensures that even if client-side interface elements are hidden from low-privileged users, the underlying functionality remains reachable and exploitable through manual request crafting."
}
CVE-2026-62650: Reyrolle 7SR5 RBAC Bypass (HIGH Severity, CVSS: 8.8) - Sceawere