Description
An improper authorization vulnerability in the end-of-life versions of RTU500’s web application allows an authenticated user to trigger the RTU500 to reboot through the reset endpoint. Successful exploitation could cause temporary device unavailability and disruption of its intended operation.
Published: 2026-09-29
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Device reboot causes temporary denial of service
Action: Upgrade Firmware
AI Analysis

Impact

An improper authorization flaw in the web application of Hitachi Energy’s RTU500 series allows an authenticated user to call a reset endpoint that forces the device to reboot. The attacker simply needs valid credentials and can cause the RTU500 to become temporarily unavailable. This disruption can halt the device’s intended operation, presenting a denial‑of‑service risk for any critical process relying on the RTU500.

Affected Systems

The vulnerability affects end‑of‑life versions of the RTU500 series Customer Management Unit firmware supplied by Hitachi Energy. No specific firmware revisions are listed, so any unreleased or legacy RTU500 firmware in the field may be susceptible if it has not been upgraded beyond the end‑of‑life threshold.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1 % suggests a low probability of exploitation. The flaw is not designated in CISA’s KEV catalog, further implying limited real‑world use. However, should an attacker gain authenticated access, they can force a reboot and disrupt services. The primary attack vector is the exposed web interface and requires legitimate credentials as the only prerequisite.

Generated by OpenCVE AI on September 29, 2026 at 15:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Replace the end‑of‑life RTU500 firmware with the latest supported firmware from Hitachi Energy
  • Disable or restrict access to the reset endpoint on the web interface, ensuring only authorized personnel can trigger reboots
  • Deploy network segmentation and monitor for unauthorized reboot attempts, logging and alerting on reset API usage

Generated by OpenCVE AI on September 29, 2026 at 15:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Title Authenticated Reset Endpoint Causes Device Reboot in Hitachi Energy RTU500

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description An improper authorization vulnerability in the end-of-life versions of RTU500’s web application allows an authenticated user to trigger the RTU500 to reboot through the reset endpoint. Successful exploitation could cause temporary device unavailability and disruption of its intended operation.
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Hitachi Energy

Published:

Updated: 2026-09-29T15:05:10.350Z

Reserved: 2026-05-07T05:51:59.463Z

Link: CVE-2026-8067

cve-icon Vulnrichment

Updated: 2026-09-29T15:05:05.788Z

cve-icon NVD

Status : Received

Published: 2026-09-29T10:17:13.397

Modified: 2026-09-29T15:17:30.997

Link: CVE-2026-8067

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T15:45:18Z

Weaknesses