CVE-2026-8067: CWE-862 Missing authorization in Hitachi Energy RTU500 series CMU firmware
An improper authorization vulnerability in the end-of-life versions of RTU500’s web application allows an authenticated user to trigger the RTU500 to reboot through the reset endpoint. Successful exploitation could cause temporary device unavailability and disruption of its intended operation.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-8067) in Hitachi Energy RTU500 series CMU firmware is due to missing authorization controls in the web application's reset endpoint. Authenticated users with low privileges can cause the device to reboot, leading to temporary denial of service. The issue affects firmware versions from 9.0 up to but excluding 12.0. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) reflects network attack vector, low attack complexity, requiring privileges, no user interaction, unchanged scope, no confidentiality or integrity impact, but high availability impact.
Potential Impact
Successful exploitation causes temporary device unavailability by forcing a reboot, disrupting the intended operation of the RTU500 device. There is no impact on confidentiality or integrity. The disruption could affect operational continuity but does not allow data compromise or unauthorized data modification.
Mitigation Recommendations
No patch or official fix information is provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict authenticated user access to the web application to trusted personnel only to reduce risk of exploitation.
CVE-2026-8067: CWE-862 Missing authorization in Hitachi Energy RTU500 series CMU firmware
Description
An improper authorization vulnerability in the end-of-life versions of RTU500’s web application allows an authenticated user to trigger the RTU500 to reboot through the reset endpoint. Successful exploitation could cause temporary device unavailability and disruption of its intended operation.
CVSS v3.1
Score 6.5medium
Affected software
Hitachi Energy
RTU500 series CMU firmware
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-8067) in Hitachi Energy RTU500 series CMU firmware is due to missing authorization controls in the web application's reset endpoint. Authenticated users with low privileges can cause the device to reboot, leading to temporary denial of service. The issue affects firmware versions from 9.0 up to but excluding 12.0. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) reflects network attack vector, low attack complexity, requiring privileges, no user interaction, unchanged scope, no confidentiality or integrity impact, but high availability impact.
Potential Impact
Successful exploitation causes temporary device unavailability by forcing a reboot, disrupting the intended operation of the RTU500 device. There is no impact on confidentiality or integrity. The disruption could affect operational continuity but does not allow data compromise or unauthorized data modification.
Mitigation Recommendations
No patch or official fix information is provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict authenticated user access to the web application to trusted personnel only to reduce risk of exploitation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Hitachi Energy
- Date Reserved
- 2026-05-07T05:51:59.463Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abb897df7a7c54106284f21
Added to database: 09/29/2026, 09:48:45 UTC
Last enriched: 09/29/2026, 10:05:08 UTC
Last updated: 09/29/2026, 18:20:12 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.