VYPR
advisoryPublished Oct 6, 2026· 1 source

Critical Vulnerabilities in End-of-Life Hitachi Energy RTU500 Devices Pose Significant ICS Risk

CISA and Dragos have identified multiple critical vulnerabilities in legacy Hitachi Energy RTU500 CMU firmware versions, potentially allowing unauthenticated attackers to compromise industrial control systems.

CISA, in coordination with Dragos, has issued a stark warning regarding critical vulnerabilities affecting end-of-life firmware versions of Hitachi Energy's RTU500 Remote Terminal Unit (RTU) Communication Module (CMU). These vulnerabilities, present in versions 11.x and prior, pose a significant risk to industrial control systems (ICS) within the energy sector and other critical infrastructure environments worldwide.

The identified flaws include CVE-2026-8065, an authentication bypass vulnerability that allows unauthenticated attackers to upload arbitrary firmware via a crafted POST request. This could lead to the modification of device functionality or compromise the integrity and availability of the RTU. Another critical vulnerability, CVE-2026-8066, is a directory traversal flaw in the file upload functionality. Exploiting this allows an unauthenticated attacker to write or overwrite arbitrary files on the device's file system, potentially leading to unauthorized data modification or operational disruption.

Further compounding the risk is CVE-2026-8067, an improper authorization vulnerability within the RTU500's web application. This flaw enables an authenticated user to trigger a device reboot through a reset endpoint, which could cause temporary unavailability and disrupt operations. The advisory also lists older vulnerabilities, CVE-2010-2965 and CVE-2014-9195, which are related to the underlying VxWorks operating system used in some legacy firmware versions, and CVE-2023-46143, though details for these are less prominent in the current advisory.

Hitachi Energy acknowledges that these vulnerabilities are associated with legacy firmware versions developed under older cybersecurity requirements and threat landscapes. The company emphasizes that these end-of-life versions no longer incorporate many of the security controls and hardening measures found in modern ICS. While currently supported RTU500 CMU firmware versions are not affected, the likelihood of exploitation in the unsupported versions is high due to their inherent weaknesses and the increasing sophistication of threat actors targeting critical infrastructure.

The CVSS scores for the primary vulnerabilities highlight the severity of the risks. CVE-2026-8065 and CVE-2026-8066 are rated as CRITICAL with a base score of 9.1, indicating a high potential for impact on confidentiality, integrity, and availability. CVE-2026-8067 is rated MEDIUM with a base score of 6.5, still posing a notable risk to device availability.

Given that the affected firmware versions are end-of-life and no longer receive security updates, Hitachi Energy strongly recommends that customers upgrade to a currently supported RTU500 firmware version. Specifically, the company advises upgrading to version 12.7.8 or 13.9.1, or the latest available supported version. Implementing defense-in-depth measures and adhering to cybersecurity best practices are also crucial steps to mitigate risks and enhance the overall security posture of operational environments.

This advisory serves as a critical reminder of the ongoing threats to operational technology (OT) and the importance of maintaining up-to-date firmware for industrial control systems. The exploitation of end-of-life devices, particularly those controlling critical infrastructure, can have severe consequences, ranging from data breaches to physical disruptions. Organizations relying on these systems must prioritize timely patching and upgrades to safeguard their operations against evolving cyber threats.

Synthesized by Vypr AI