Description
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The device firmware contains binaries from which debugging symbols have not been removed. This could allow an unauthenticated attacker with access to the publicly available firmware update files to more easily reverse engineer the device's firmware, facilitating the identification of further vulnerabilities.
Published: 2026-09-08
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw lies in the presence of debugging symbols in the firmware binaries of the Reyrolle 7SR5 device, all versions prior to V2.70. Because these symbols are not stripped, an attacker who obtains a firmware file could analyze the code more readily, which may reveal additional weaknesses or allow the creation of targeted exploits. The vulnerability therefore presents an information‑exposure risk that can lower the barrier to discovering new flaws, but it does not directly grant code execution or data exfiltration at the time of exploitation.

Affected Systems

Siemens Reyrolle 7SR5 devices running firmware versions older than V2.70 are impacted. Any installation of these firmware images, irrespective of configuration, maintains the debugging symbols that facilitate reverse engineering.

Risk and Exploitability

The CVSS score of 6.9 classifies the risk as medium. Without an EPSS value, the current exploitation probability cannot be quantified, but the KEV status confirms the vulnerability is not yet catalogued as a known exploited vulnerability. An unauthenticated attacker with access to the publicly available firmware update files—likely the download location—can exploit this weakness by reverse engineering; therefore the attack vector is inferable from the description. No known exploits or detailed attack paths have been reported at this time.

Generated by OpenCVE AI on September 8, 2026 at 09:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device to the latest firmware release that removes debugging symbols
  • Ensure firmware files are cryptographically signed and verify the signature before installation
  • Restrict public access to firmware update repositories so that only authenticated personnel can download images

Generated by OpenCVE AI on September 8, 2026 at 09:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The device firmware contains binaries from which debugging symbols have not been removed. This could allow an unauthenticated attacker with access to the publicly available firmware update files to more easily reverse engineer the device's firmware, facilitating the identification of further vulnerabilities.
Weaknesses CWE-215
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2026-09-08T08:11:33.091Z

Reserved: 2026-07-14T16:24:23.430Z

Link: CVE-2026-62652

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-08T09:18:17.340

Modified: 2026-09-08T09:18:17.340

Link: CVE-2026-62652

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T09:30:07Z

Weaknesses
  • CWE-215

    Insertion of Sensitive Information Into Debugging Code