Hitachi Energy RTU500
CISA warns end-of-life Hitachi Energy RTU500 firmware has critical unauthenticated flaws, including arbitrary firmware upload.
CISA republished a Hitachi Energy advisory, based on Dragos findings, for end-of-life RTU500 series CMU firmware 11.x and earlier used in the energy sector. CVE-2026-8065 (CVSS 9.1) allows unauthenticated firmware upload, CVE-2026-8066 (CVSS 9.1) allows unauthenticated arbitrary file writes, and CVE-2026-8067 (CVSS 6.5) lets a low-privileged user reboot the device. Legacy issues include CVE-2010-2965, the Wind River VxWorks WDB agent on UDP port 17185, listed at CVSS 9.8, plus CVE-2014-9195 and CVE-2023-46143. Supported firmware is unaffected; Hitachi Energy recommends 12.7.8, 13.9.1, or later. Exploitation is not reported.