ZeroHour

CVE-2026-62646

large

Predictable session tokens allow authentication bypass in Siemens Reyrolle 7SR5

CVSS 4.0
9.1 critical
EPSS
<1%p24
Published
()
Modified
AI analysis

CVE-2026-62646 is a weak session-identifier generation flaw (CWE-331) in the web interface of Siemens Reyrolle 7SR5 protection relays, where session tokens are generated with insufficient randomness and therefore carry low entropy. Because the tokens can be predicted or brute-forced within a feasible number of attempts, an unauthenticated remote attacker who can reach the device's web server can derive valid session identifiers without knowing any credentials. Successful exploitation bypasses authentication and gives the attacker access to the relay's management interface, with high confidentiality and high integrity impact reflected in the 9.1 CVSS 4.0 score (note the high attack complexity, since success depends on feasibly guessing usable tokens). Operators of Reyrolle 7SR5 relays running any firmware below V2.70 are affected, primarily utilities and industrial sites whose relays expose a web management interface reachable beyond the local substation network. Exploitation has not been observed: no public proof-of-concept exists, the issue is not in CISA's KEV catalog, and EPSS is 0.3%.

What to do: Upgrade affected Reyrolle 7SR5 relays to firmware V2.70 or later. Until upgraded, restrict the relay's web interface to trusted management networks (ACLs, VPN, or OT/IT segmentation) or disable remote web access, since exploitation requires network reachability and feasible token guessing. Inventory which 7SR5 relays have the web server enabled and exposed, and monitor for unexpected authenticated sessions.

Affected
Siemens Reyrolle 7SR5All versions < V2.70
Estimated exposure
large≈10k–100k relays deployed globally (installed-base estimate; the subset with remotely reachable web interfaces is unknown) — No install counts were provided, so the estimate assumes a global installed base in the tens of thousands for this widely deployed Siemens utility protection relay line, with actual exposure limited to devices whose web interface is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A session identifier is generated using an algorithm with insufficient randomness, resulting in a token with low entropy that can be predicted or brute-forced within a feasible number of attempts. This could allow an unauthenticated remote attacker to derive valid session identifiers and bypass authentication.

Weakness
CWE-331
Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Siemens Reyrolle 7SR5

CISA advisory covers 14 vulnerabilities, CVSS 9.8, in Siemens Reyrolle 7SR5 energy-sector protection relays before V2.70.

CISA advisory ICSA-26-258-05 covers 14 vulnerabilities in Siemens Reyrolle 7SR5 protection relays before V2.70, used in the energy sector worldwide, with aggregate CVSS v3 of 9.8. Flaws include Cesanta Mongoose web server issues (CVE-2024-42384 through CVE-2024-42392) and new bugs such as web-interface session-ID exposure enabling authentication bypass (CVE-2026-62645, CVSS 9.8), predictable session tokens (CVE-2026-62646, CVE-2026-62647), and pre-auth out-of-bounds writes (CVE-2026-62648). Siemens has released V2.70 and recommends updating to the latest version.