Hitachi Energy RTU500
This advisory details vulnerabilities within Hitachi Energy’s RTU500 product, specifically CMU Firmware versions 12.7.1 through 13.8.1. These vulnerabilities, primarily CWE-476 (NULL Pointer Dereference) and CWE-190 (Integer Overflow or Wraparound), lead to Denial of Service conditions when processing malformed PKCS#12 files or specific IEC 61850 configurations. Immediate remediation through firmware updates to version 13.8.2 is recommended.
Hitachi Energy has identified several vulnerabilities impacting its RTU500 product, a critical component in dam, energy, and water/wastewater infrastructure. The vulnerabilities, detailed through CVE identifiers including CVE-2025-69421, CVE-2026-24515, CVE-2026-25210, CVE-2026-32776, CVE-2026-32777, CVE-2026-32778, CVE-2026-8479, and CWE-476, relate to the processing of PKCS#12 files and IEC 61850 functionality. Specifically, a NULL pointer dereference can occur when handling malformed PKCS#12 files, leading to application crashes and Denial of Service. Integer overflow vulnerabilities also exist within the handling of XML external entity parameters, potentially causing similar denial-of-service outcomes. These vulnerabilities are exacerbated by configurations utilizing IEC 61850, increasing the attack surface. The vulnerabilities are primarily focused on denial of service, preventing exploitation for code execution or information disclosure.