Hitachienergy Vulnerabilities
Comprehensive security vulnerability database for Hitachienergy products
5
0
5
0
Severity Distribution
| Description | Vendor / Product | Exploit Status | |||
|---|---|---|---|---|---|
| CVE-2026-2460 | 7.6 | An attacker with low-level access can exploit a vulnerability in the REB500 firmware to change files and directories they shouldn't be able to modify. This requires the attacker to already have authenticated access to the system, making it a serious risk if such users are compromised. | hitachienergyreb500 firmware | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-2459 | 7.4 | This vulnerability allows an attacker with an Installer role to access and change files in directories they shouldn't be able to, potentially compromising the system's integrity. However, the attacker must already be authenticated as a user with the Installer role to exploit this weakness. | hitachienergyreb500 firmware | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-1773 | 8.7 | This vulnerability allows an attacker to cause a Denial of Service, making the system unresponsive, by sending invalid data frames if the device is set up for bi-directional communication using the IEC 60870-5-104 protocol. Even though enabling secure communication can reduce the risk, it does not completely fix the issue. | hitachienergyrtu540 firmware | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-1772 | 5.3 | An attacker can access sensitive user management information from the RTU500 device, even without proper permissions, by using tools like browser development utilities. This information is not directly available through the device's web interface, so the attacker needs to know how to use these additional tools to exploit the vulnerability. | hitachienergyrtu520 firmware | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2023-5769 | 6.1 | An attacker could inject malicious scripts into the web interface of the RTU500 series devices, potentially allowing them to steal sensitive information or perform actions on behalf of legitimate users. This vulnerability occurs because the device does not properly filter user input, making it easier for attackers to exploit it if they can access the webserver. | hitachienergyrtu520 firmware | Exploit Available | over 2 years agoDec 14, 2023 |
About Hitachienergy Security
This page tracks all publicly disclosed security vulnerabilities (CVEs) affecting Hitachienergy products. Our database is updated in real-time from the National Vulnerability Database (NVD) and enriched with exploit information from GitHub and other security research sources.
Each CVE listing includes CVSS severity scores, exploit availability status, AI-powered vulnerability summaries, and links to official patches and security advisories.