Description
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The length of the URL component contained in pre-authenticated HTTP messages is not properly validated before appending additional data to it, resulting in an out-of-bounds write condition in memory. This could allow an unauthenticated remote attacker to crash the affected device, causing a reboot and resulting in a denial-of-service condition.
Published: 2026-09-08
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Reyrolle 7SR5 fails to validate the length of the URL component in pre‑authenticated HTTP messages before appending additional data. This missing validation results in an out‑of‑bounds write for an attacker who supplies an excessively long URL component, causing a memory corruption that crashes the HTTP stack and forces the device to reboot. The crash precludes normal operation and constitutes a denial‑of‑service.

Affected Systems

Siemens Reyrolle 7SR5, all firmware versions prior to V2.70 are affected.

Risk and Exploitability

The CVSS score is 8.7, indicating a high‑severity vulnerability. EPSS information is not available, and the flaw is not listed in CISA’s KEV catalog. The attack vector requires an unauthenticated HTTP connection; no credentials or privileged access are needed. A remote attacker can simply send a crafted HTTP request to trigger the overflow, which typically results in a device reboot and service interruption.

Generated by OpenCVE AI on September 8, 2026 at 09:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device firmware to version V2.70 or later, which contains the hot‑fix for the overflow.
  • If upgrading is currently unfeasible, limit external access to the HTTP interface by placing the device behind a firewall or disabling the interface from untrusted networks.
  • Continuously monitor device logs for unexpected reboots or crash indicators and apply any future vendor patches as soon as they are released.

Generated by OpenCVE AI on September 8, 2026 at 09:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The length of the URL component contained in pre-authenticated HTTP messages is not properly validated before appending additional data to it, resulting in an out-of-bounds write condition in memory. This could allow an unauthenticated remote attacker to crash the affected device, causing a reboot and resulting in a denial-of-service condition.
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2026-09-08T08:11:29.868Z

Reserved: 2026-07-14T16:24:23.430Z

Link: CVE-2026-62648

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-08T09:18:16.963

Modified: 2026-09-08T09:18:16.963

Link: CVE-2026-62648

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T09:30:07Z

Weaknesses