ZeroHour

CVE-2026-62648

moderate

Out-of-bounds write in Siemens Reyrolle 7SR5 relays enables remote DoS

CVSS 4.0
8.7 high
EPSS
<1%p26
Published
()
Modified
AI analysis

Siemens reports an out-of-bounds write (CWE-787) in the HTTP handling of the Reyrolle 7SR5 protection relay, where the length of the URL component in pre-authenticated HTTP messages is not validated before additional data is appended to it. A remote, unauthenticated attacker can trigger the flaw by sending crafted HTTP messages with an oversized URL directly to the device, corrupting memory and crashing it. The attacker gains a denial-of-service condition: the relay crashes and reboots, interrupting its operation, with no confidentiality or integrity impact per the CVSS 4.0 score (availability impact only). Any Reyrolle 7SR5 unit running a version prior to V2.70 with its HTTP/web interface enabled and reachable by an attacker is affected, though these relays typically sit on utility or industrial OT networks rather than the open internet. There is currently no known exploitation, no public proof-of-concept, and the flaw is not in CISA KEV, with a low EPSS probability (0.3%) of exploitation in the next 30 days.

What to do: Upgrade affected Reyrolle 7SR5 devices to firmware V2.70 or later, per Siemens. Until patched, restrict network access to the relay's HTTP/web management interface so it is reachable only from trusted engineering or SCADA networks, and monitor for unexpected device reboots. Operators of substations or industrial sites using 7SR5 relays should inventory firmware versions and check Siemens' ProductCERT advisory for updates.

Affected
Siemens Reyrolle 7SR5All versions < V2.70
Estimated exposure
moderatelikely on the order of thousands to tens of thousands of deployed relays worldwide, but only units with the HTTP management interface reachable from an… — No public install counts are available, so this is estimated from the typical global deployment pattern of Siemens Reyrolle 5-series feeder protection relays across utility substations and industrial power systems, most of which are not…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The length of the URL component contained in pre-authenticated HTTP messages is not properly validated before appending additional data to it, resulting in an out-of-bounds write condition in memory. This could allow an unauthenticated remote attacker to crash the affected device, causing a reboot and resulting in a denial-of-service condition.

Weakness
CWE-787
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Siemens Reyrolle 7SR5

CISA advisory covers 14 vulnerabilities, CVSS 9.8, in Siemens Reyrolle 7SR5 energy-sector protection relays before V2.70.

CISA advisory ICSA-26-258-05 covers 14 vulnerabilities in Siemens Reyrolle 7SR5 protection relays before V2.70, used in the energy sector worldwide, with aggregate CVSS v3 of 9.8. Flaws include Cesanta Mongoose web server issues (CVE-2024-42384 through CVE-2024-42392) and new bugs such as web-interface session-ID exposure enabling authentication bypass (CVE-2026-62645, CVSS 9.8), predictable session tokens (CVE-2026-62646, CVE-2026-62647), and pre-auth out-of-bounds writes (CVE-2026-62648). Siemens has released V2.70 and recommends updating to the latest version.