VYPR
advisoryPublished Sep 15, 2026· 1 source

Siemens Reyrolle 7SR5 Devices Vulnerable to Multiple Exploits, Including Remote Code Execution

CISA alerts users to critical vulnerabilities in Siemens Reyrolle 7SR5 devices, stemming from an outdated web server component, with patches now available.

Siemens has released a critical security update for its Reyrolle 7SR5 industrial control system devices, addressing a suite of vulnerabilities that could allow attackers to compromise the system. The advisory, published by CISA as ICS-ALERT-26-258-05, highlights that versions prior to 2.70 are affected by multiple flaws, primarily originating from the Cesanta Mongoose Web Server component used within the devices.

The vulnerabilities span a range of severity, including integer overflows, improper neutralization of input, out-of-bounds writes, and authentication bypass mechanisms. Specifically, CVE-2024-42384 and CVE-2024-42386 detail how an attacker could send malformed TLS packets to cause a segmentation fault, potentially leading to denial-of-service conditions. Other flaws, such as CVE-2024-42385 and CVE-2024-42392, relate to improper handling of certificate data and input strings, which could also lead to application crashes or unexpected behavior.

More concerning are the vulnerabilities that could enable unauthorized access and control. CVE-2026-62645 points to information exposure through the web interface that could allow an attacker to calculate session IDs, potentially bypassing authentication. Similarly, CVE-2026-62646 describes an insufficient entropy in session identifier generation, making tokens predictable and vulnerable to brute-force attacks. These issues collectively present a significant risk to the integrity and availability of the affected industrial systems.

The affected products are Siemens Reyrolle 7SR5 devices with versions earlier than V2.70. These devices are deployed globally across critical infrastructure sectors, particularly within the energy industry. The broad applicability and critical nature of these systems underscore the importance of timely patching and mitigation efforts.

Siemens has addressed these vulnerabilities by releasing version 2.70 of the Reyrolle 7SR5 firmware. The company strongly recommends that all users update to this latest version as soon as possible to remediate the identified security risks. A direct link to the vendor's support page for the update is provided in the advisory for user convenience.

While the advisory lists numerous CVEs, the most critical, CVE-2026-62645, carries a CVSS v3.1 base score of 9.8 (Critical), indicating a severe risk of unauthorized access and control. Other high-severity vulnerabilities include CVE-2024-42386 (8.2 HIGH) and CVE-2026-62646 (7.4 HIGH), further emphasizing the urgent need for remediation.

This advisory serves as a crucial reminder of the ongoing security challenges within the Industrial Internet of Things (IIoT) and Operational Technology (OT) sectors. The reliance on components like the Cesanta Mongoose Web Server, when not kept up-to-date, can introduce a cascade of vulnerabilities that attackers can exploit to gain a foothold in critical infrastructure. Organizations are urged to consult the CISA advisory and Siemens' guidance to ensure their systems are protected.

Synthesized by Vypr AI