Hitachi Energy REB500
Hitachi Energy REB500 8.3.3.1 and earlier can be crashed via libexpat flaws in IEC 61850 parsing.
CISA advisory ICSA-26-279-05 says Hitachi Energy REB500 versions 8.3.3.1 and earlier are affected by two libexpat issues in IEC 61850 functionality. CVE-2024-8176 is uncontrolled recursion that an authenticated user can trigger with a crafted IEC 61850 message, causing denial of service or possible memory corruption. CVE-2025-59375, in Expat before 2.7.2, lets authenticated users force large memory allocations from a small document. Both score CVSS 3.1 6.5; the fix is version 8.3.4.0, and SSVC lists no exploitation.
36