AI analysis
CVE-2026-62654 is a download-of-code-without-integrity-check flaw (CWE-494) in Siemens Reyrolle 7SR5 protection relays: when a special maintenance mode is active, the device downloads and executes program code from a network server without verifying its authenticity or integrity. Maintenance mode is activated with a physical key sequence during device boot, so exploiting the flaw requires an attacker to have physical access to the relay; no authentication or user interaction beyond that is required. An attacker who triggers this mode can upload and execute arbitrary, unsigned code on the device, with high confidentiality, integrity, and availability impact on the relay itself. All Reyrolle 7SR5 versions below V2.70 are affected; these relays are installed in utility and industrial substations and are generally not internet-exposed, limiting realistic attack paths to physically present personnel or intruders. There is currently no public proof-of-concept, no CISA KEV listing, and no known exploitation, with EPSS estimating only a 0.1% probability of exploitation within 30 days.
What to do: Update affected Reyrolle 7SR5 relays to V2.70 or later per Siemens ProductCERT guidance. Until upgraded, restrict physical access to the relays (locked switchgear rooms and cabinets), treat the network server the device loads maintenance-mode code from as a trusted, controlled resource, and monitor/supervise any reboot or maintenance-mode activity on installed units.
Affected
| Siemens Reyrolle 7SR5 | All versions < V2.70 |
Estimated exposure
largeLikely tens of thousands of installed 7SR5 relays worldwide (fleet estimate; none typically internet-exposed) — No public install-base count exists for this product, so the order of magnitude is estimated from typical deployment patterns of Siemens Reyrolle numerical protection relays, which are installed per bay in utility and industrial…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A special maintenance mode can be activated via a physical key sequence during device boot, in which the device downloads and executes program code from a network server without verifying its authenticity or integrity. This could allow an attacker with physical access to the device to upload and execute arbitrary, unsigned code.