ZeroHour

CVE-2026-62650

Authenticated privilege escalation (RBAC bypass) in Siemens Reyrolle 7SR5 web UI

CVSS 4.0
8.7 high
EPSS
<1%p25
Published
()
Modified
AI analysis

Siemens Reyrolle 7SR5 protection relays running firmware before V2.70 fail to properly enforce server-side authorization checks in the web-based management interface (CWE-288). An authenticated, low-privileged remote attacker can bypass role-based access control by manipulating request data, because authorization decisions are not correctly validated on the server. Successful exploitation elevates the attacker from a low-privileged account to administrative level on the device, allowing full management and configuration actions; CVSS 4.0 rates the confidentiality, integrity and availability impact on the vulnerable system as high (8.7). Any Reyrolle 7SR5 unit with the web interface enabled and firmware below V2.70 is affected, typically in utility substation and industrial power deployments where the interface is reachable from an operational network. As of publication there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates a ~0.3% probability of exploitation within 30 days (25th percentile).

What to do: Upgrade Reyrolle 7SR5 firmware to V2.70 or later per the Siemens ProductCert advisory. Until patched, restrict the relay's web management interface to trusted management networks, minimize or remove low-privileged web accounts, and check device configurations/logs for unexpected changes. Exploitation requires valid low-privileged credentials, so account hygiene and network segmentation are the key interim mitigations.

Affected
Siemens Reyrolle 7SR5All versions < V2.70
Estimated exposure
unknown (plausibly thousands to tens of thousands of deployed relay devices; no public install or exposure counts) — No public install-count, market-share, or internet-exposure scan data exists for this specialized substation protection relay line, so the magnitude is inferred from deployment patterns: relays are installed per feeder/bay across many…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Server-side authorization checks in the web-based management interface are not properly enforced, allowing role-based access control (RBAC) restrictions to be bypassed through manipulation of request data. This could allow an authenticated, low-privileged remote attacker to escalate privileges to an administrative level.

Weakness
CWE-288
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Siemens Reyrolle 7SR5

CISA advisory covers 14 vulnerabilities, CVSS 9.8, in Siemens Reyrolle 7SR5 energy-sector protection relays before V2.70.

CISA advisory ICSA-26-258-05 covers 14 vulnerabilities in Siemens Reyrolle 7SR5 protection relays before V2.70, used in the energy sector worldwide, with aggregate CVSS v3 of 9.8. Flaws include Cesanta Mongoose web server issues (CVE-2024-42384 through CVE-2024-42392) and new bugs such as web-interface session-ID exposure enabling authentication bypass (CVE-2026-62645, CVSS 9.8), predictable session tokens (CVE-2026-62646, CVE-2026-62647), and pre-auth out-of-bounds writes (CVE-2026-62648). Siemens has released V2.70 and recommends updating to the latest version.