Impact
An authentication bypass flaw exists in the firmware update endpoint of Hitachi Energy RTU500 series CMU firmware. The vulnerability permits an unauthenticated attacker to send a crafted POST request to upload arbitrary firmware onto the device. Successful exploitation would let the attacker alter device behavior, corrupt its operation, or deny service, thereby compromising confidentiality, integrity, and availability of the affected equipment.
Affected Systems
The flaw affects Hitachi Energy RTU500 series CMU firmware running on end-of-life versions. Users operating these models must verify whether their units are running legacy firmware that still exposes the vulnerable update endpoint.
Risk and Exploitability
The CVSS score of 9.1 indicates severe risk, while the EPSS score of less than 1% suggests a low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through network reachability to the firmware update endpoint; an attacker can exploit the bypass without prior authentication and install malicious firmware. The impact could be complete device takeover or disruption.
OpenCVE Enrichment