Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-8066: Hitachi Energy RTU500 firmware lets attacker write files
CVE-2026-8066 · published 3 days ago
Summary
The RTU500 series firmware has a weakness in its file upload feature that allows anyone on the network to place or replace files on the device. This could let an attacker change important data or stop the device from working correctly. Apply any available firmware updates, move to a supported version, and limit network access to the device.
What to do
- Update hitachi energy rtu500 series cmu firmware to version 12.0 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| hitachi energy | rtu500 series cmu firmware | < 12.0 |
Original advisory text
A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to write or overwrite arbitrary files on the de...
A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to write or overwrite arbitrary files on the device file system. Depending on the files affected, successful exploitation could result in unauthorized modification of device data or disruption of the device’s intended operation.
Internet-facing
14 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker partial control
Type
CWE-23Relative Path Traversal
Timeline
Published29 Sep 2026
Updated1 Oct 2026
First seen29 Sep 2026
Track software like this
Free during beta