Sceawere

Vulnerability Detail

CVE-2026-8067UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

RTU500 Unauthorized Reset Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
15h ago
Vendor
Hitachi Energy
Product
RTU500 series CMU firmware
Attack Type
CWE-862 Missing authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

An improper authorization vulnerability in the RTU500’s web application allows an authenticated user to trigger the RTU500 to reboot through the reset endpoint. Successful exploitation could cause temporary device unavailability and disruption of its intended operation.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-29T10:17:13.397Z",
  "pubdate": "2026-09-29T10:17:13.397Z",
  "executiveSummary": "An improper authorization vulnerability exists within the web application of the RTU500, allowing an authenticated user to initiate a device reset sequence.\nThis vulnerability is classified as an improper authorization flaw, which permits an attacker to perform a sensitive administrative operation—specifically, system rebooting—without the requisite authorization level.\nThe primary impact of this vulnerability is a denial-of-service (DoS) condition, resulting in temporary device unavailability and the subsequent disruption of industrial control processes governed by the RTU500.\nExploitation requires the attacker to possess an active authenticated session within the RTU500 web interface.\nThe risk implication is significant for critical infrastructure environments where device uptime is essential for operational continuity and safety.\nThere are no requirements for specialized hardware or deep packet inspection; a standard HTTP request to the designated reset endpoint is sufficient to trigger the reboot.",
  "technicalDetails": "The vulnerability resides within the web server component of the RTU500 series, specifically concerning the access control logic governing administrative endpoints.\nThe root cause is a failure in the authorization mechanism to verify that a requesting user holds the appropriate administrative privileges before executing commands associated with the device's lifecycle management.\nThe web application exposes a specific reset endpoint—intended for authorized administrative use—which fails to adequately validate the session tokens or role-based access control (RBAC) attributes against the requested operation.\nExploitation follows a straightforward attack flow: An attacker establishes an authenticated session with the RTU500 web application. Once authenticated, the attacker crafts an HTTP request targeting the reset endpoint. Because the underlying application logic performs insufficient checks, the web server executes the request, triggering the device's internal power management or firmware reset function.\nThe vulnerable component is the web interface controller, which manages the routing and execution of administrative API calls. By bypassing the expected authorization flow, an authenticated low-privileged user can successfully invoke the command, forcing the RTU500 to re-initialize its operation.\nThe payload behavior involves the transmission of an HTTP request directed at the reset function. When processed, the backend system initiates a hardware or software reboot sequence, causing the device to enter a state of unavailability during the boot cycle. This results in an immediate loss of communication with supervisory control and data acquisition (SCADA) or master systems, potentially triggering fail-safe modes in connected field devices.\nPost-exploitation, the device will remain offline until the boot process is complete, leading to a temporary interruption in process monitoring and control functions. The vulnerability does not grant further escalation to the underlying operating system shell, but the capability to repeatedly induce a reboot can be used to maintain a persistent denial-of-service state on the targeted RTU500 hardware."
}
CVE-2026-8067: RTU500 Unauthorized Reset Vulnerability (MEDIUM Severity, CVSS: 6.5) | Sceawere