Description
A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to write or overwrite arbitrary files on the device file system. Depending on the files affected, successful exploitation could result in unauthorized modification of device data or disruption of the device’s intended operation.
Published: 2026-09-29
Score: 9.1 Critical
EPSS: 1.2% Low
KEV: No
Impact: Unauthorized Data Modification or Disruption
Action: Patch Immediately
AI Analysis

Impact

A directory traversal flaw (CWE-23) in the firmware of Hitachi Energy RTU500 series devices lets an unauthenticated attacker write arbitrary files to the system. By overwriting configuration or executable files, an attacker could modify device data or disrupt operation, disabling critical functions.

Affected Systems

The vulnerability affects Hitachi Energy RTU500 series RTU firmware that has reached end‑of‑life. No specific version numbers are provided; any device running the affected firmware is potentially compromised.

Risk and Exploitability

The CVSS score of 9.1 indicates high severity, and the EPSS score of 0.01157 suggests that exploitation is plausible, although not extremely common. The vulnerability is not listed in the CISA KEV catalog, but its impact and ease of exploitation make it a significant risk. An attacker would likely exploit the weakness by sending a crafted upload request that triggers the directory traversal, uploading a file that implements malicious logic or alters configuration. Because no authentication is required, anyone with network access to the device could carry out the attack.

Generated by OpenCVE AI on September 29, 2026 at 17:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update provided by Hitachi Energy for RTU500 series devices.
  • Disable the file upload capability or restrict it to trusted network segments.
  • Implement file integrity monitoring and alerting for unauthorized modifications.
  • Ensure network segmentation isolates RTU devices from untrusted traffic.

Generated by OpenCVE AI on September 29, 2026 at 17:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title Directory Traversal Allowing Arbitrary File Write in Hitachi Energy RTU500 Firmware

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to write or overwrite arbitrary files on the device file system. Depending on the files affected, successful exploitation could result in unauthorized modification of device data or disruption of the device’s intended operation.
Weaknesses CWE-23
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Hitachi Energy

Published:

Updated: 2026-09-29T15:52:33.807Z

Reserved: 2026-05-07T05:51:57.867Z

Link: CVE-2026-8066

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T10:17:13.250

Modified: 2026-09-29T21:39:02.570

Link: CVE-2026-8066

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T17:45:17Z

Weaknesses
  • CWE-23

    Relative Path Traversal