important · Firmware — industrial
Unauthenticated requests can upload arbitrary firmware to end-of-life Hitachi Energy RTU500 controllers.
Affects
Hitachi Energy RTU500 Series CMU firmware, used by substation remote terminal units.
Network reachability to the update endpoint is enough to submit attacker-selected firmware content.
Detail and 3 sources
Public code stops at a harmless marker payload: installation, boot and persistence on stock hardware remain unproven, and no corrected release was established for the end-of-life branches.
Sources
ResearchCVE-2026-8065 - Vulnerability-LookupCode / PoCGitHub - murrez/CVE-2026-8065: CVE-2026-8065 PoC: Hitachi Energy RTU500 unauth firmware update bypass (CWE-306, CVSS 9.1). IoT/OT colored check + mass exploit — RTU500 fingerprint, firmware endpoint probe, lab-safe upload test. https://pocbit.org/pocs/cve-2026-8065 · GitHubVendorProduct Security Incident Response Team | Hitachi Energy