AI analysis
CVE-2026-62646 is a weak session-identifier generation flaw (CWE-331) in the web interface of Siemens Reyrolle 7SR5 protection relays, where session tokens are generated with insufficient randomness and therefore carry low entropy. Because the tokens can be predicted or brute-forced within a feasible number of attempts, an unauthenticated remote attacker who can reach the device's web server can derive valid session identifiers without knowing any credentials. Successful exploitation bypasses authentication and gives the attacker access to the relay's management interface, with high confidentiality and high integrity impact reflected in the 9.1 CVSS 4.0 score (note the high attack complexity, since success depends on feasibly guessing usable tokens). Operators of Reyrolle 7SR5 relays running any firmware below V2.70 are affected, primarily utilities and industrial sites whose relays expose a web management interface reachable beyond the local substation network. Exploitation has not been observed: no public proof-of-concept exists, the issue is not in CISA's KEV catalog, and EPSS is 0.3%.
What to do: Upgrade affected Reyrolle 7SR5 relays to firmware V2.70 or later. Until upgraded, restrict the relay's web interface to trusted management networks (ACLs, VPN, or OT/IT segmentation) or disable remote web access, since exploitation requires network reachability and feasible token guessing. Inventory which 7SR5 relays have the web server enabled and exposed, and monitor for unexpected authenticated sessions.
Affected
| Siemens Reyrolle 7SR5 | All versions < V2.70 |
Estimated exposure
large≈10k–100k relays deployed globally (installed-base estimate; the subset with remotely reachable web interfaces is unknown) — No install counts were provided, so the estimate assumes a global installed base in the tens of thousands for this widely deployed Siemens utility protection relay line, with actual exposure limited to devices whose web interface is…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A session identifier is generated using an algorithm with insufficient randomness, resulting in a token with low entropy that can be predicted or brute-forced within a feasible number of attempts. This could allow an unauthenticated remote attacker to derive valid session identifiers and bypass authentication.