CWE-522 Insufficiently Protected Credentials in Schneider Electric EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller (CVE-2026-9650)
CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenticated attacker accesses credentials stored within firmware or system files. With this credential an attacker could subsequently compromise the device if they have physical access to the device.
AI Analysis
Technical Summary
This advisory covers multiple vulnerabilities identified in Schneider Electric EasyLogic T150 and Saitel DP RTU products, specifically versions up to 11.06.30. The vulnerabilities are associated with CWE-522 (Insufficiently Protected Credentials) and CWE-732 (Incorrect Permission Assignment for Critical Resource). The vendor has not provided explicit patch information or detailed technical exploit data. The advisory focuses on recommended cybersecurity best practices to mitigate risks, such as network segmentation, physical security controls, and secure remote access methods. No known exploits are reported in the wild.
Potential Impact
The vulnerabilities potentially allow unauthorized access or misuse of control and safety system components due to insufficient credential protection and improper permission assignments. This could lead to unauthorized control or disruption of industrial processes if exploited. However, no specific impact scenarios or exploit details are provided in the advisory.
Mitigation Recommendations
No official patch or fix is currently indicated. The vendor recommends following established cybersecurity best practices, including isolating control networks behind firewalls, enforcing physical access controls, securing programming modes, restricting network connections for programming software, sanitizing removable media, minimizing network exposure, and using secure remote access methods such as VPNs. These mitigations aim to reduce the attack surface and prevent unauthorized access. Patch status is not yet confirmed — check the vendor advisory SEVD-2026-160-02 for updates.
CWE-522 Insufficiently Protected Credentials in Schneider Electric EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller (CVE-2026-9650)
Description
CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenticated attacker accesses credentials stored within firmware or system files. With this credential an attacker could subsequently compromise the device if they have physical access to the device.
CVSS v4.0
Score 8.7high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This advisory covers multiple vulnerabilities identified in Schneider Electric EasyLogic T150 and Saitel DP RTU products, specifically versions up to 11.06.30. The vulnerabilities are associated with CWE-522 (Insufficiently Protected Credentials) and CWE-732 (Incorrect Permission Assignment for Critical Resource). The vendor has not provided explicit patch information or detailed technical exploit data. The advisory focuses on recommended cybersecurity best practices to mitigate risks, such as network segmentation, physical security controls, and secure remote access methods. No known exploits are reported in the wild.
Potential Impact
The vulnerabilities potentially allow unauthorized access or misuse of control and safety system components due to insufficient credential protection and improper permission assignments. This could lead to unauthorized control or disruption of industrial processes if exploited. However, no specific impact scenarios or exploit details are provided in the advisory.
Mitigation Recommendations
No official patch or fix is currently indicated. The vendor recommends following established cybersecurity best practices, including isolating control networks behind firewalls, enforcing physical access controls, securing programming modes, restricting network connections for programming software, sanitizing removable media, minimizing network exposure, and using secure remote access methods such as VPNs. These mitigations aim to reduce the attack surface and prevent unauthorized access. Patch status is not yet confirmed — check the vendor advisory SEVD-2026-160-02 for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Schneider Electric CPCERT
- Advisory Id
- SEVD-2026-160-02
- Cve Count
- 2
- Additional Cves
- ["CVE-2026-9651"]
- Cvss Version
- null
Threat ID: 6a27e97e8dd33fbd85167683
Added to database: 06/09/2026, 10:22:54 UTC
Last enriched: 06/25/2026, 20:06:44 UTC
Last updated: 07/25/2026, 08:52:04 UTC
Views: 144
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.