Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-8066: Hitachi Energy RTU500 firmware lets attacker write files

CVE-2026-8066 · published 3 days ago
Summary

The RTU500 series firmware has a weakness in its file upload feature that allows anyone on the network to place or replace files on the device. This could let an attacker change important data or stop the device from working correctly. Apply any available firmware updates, move to a supported version, and limit network access to the device.

What to do
  • Update hitachi energy rtu500 series cmu firmware to version 12.0 or later.
Affected software
VendorProductAffected versions
hitachi energy rtu500 series cmu firmware < 12.0
Original advisory text
A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to write or overwrite arbitrary files on the de...
A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to write or overwrite arbitrary files on the device file system. Depending on the files affected, successful exploitation could result in unauthorized modification of device data or disruption of the device’s intended operation.
Fix within
Internet-facing 14 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker partial control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-23Relative Path Traversal
Timeline
Published29 Sep 2026
Updated1 Oct 2026
First seen29 Sep 2026
Sources
CVE-2026-8066 · NVD
CVE-2026-8066 · MITRE
Track software like this
Free during beta