Skip to content
Threat Feed
critical advisory

Critical Vulnerabilities in End-of-Life Hitachi Energy RTU500 Firmware

End-of-life Hitachi Energy RTU500 CMU firmware versions 11.x and prior are susceptible to multiple critical vulnerabilities, including authentication bypass and path traversal, which could allow remote attackers to compromise device integrity or disrupt industrial control operations.

CVE search metadata

CVE search record: CVE-2026-8066. Severity: critical. CVSS: 9.1. EPSS: 0.74%. KEV: no. Product: RTU500 series CMU Firmware (<= 11.x), VxWorks (6.x, 5.x and earlier). Brief: Critical Vulnerabilities in End-of-Life Hitachi Energy RTU500 Firmware. Brief link: https://feed.craftedsignal.io/briefs/2026-10-hitachi-rtu500/

CVE search record: CVE-2026-8067. Severity: medium. CVSS: 6.5. EPSS: 0.32%. KEV: no. Product: RTU500 series CMU Firmware (<= 11.x), VxWorks (6.x, 5.x and earlier). Brief: Critical Vulnerabilities in End-of-Life Hitachi Energy RTU500 Firmware. Brief link: https://feed.craftedsignal.io/briefs/2026-10-hitachi-rtu500/

CVE search record: CVE-2010-2965. Severity: critical. CVSS: 9.8. EPSS: 47.37%. KEV: no. Product: RTU500 series CMU Firmware (<= 11.x), VxWorks (6.x, 5.x and earlier). Brief: Critical Vulnerabilities in End-of-Life Hitachi Energy RTU500 Firmware. Brief link: https://feed.craftedsignal.io/briefs/2026-10-hitachi-rtu500/

Hitachi Energy has issued an advisory regarding multiple security vulnerabilities affecting legacy, end-of-life (EOL) RTU500 CMU firmware versions 11.x and earlier. These firmware versions, developed under historical industry standards, lack modern security controls such as robust authentication, encrypted communications, and integrity checks. Researchers reported that these legacy systems are susceptible to several high-severity flaws, including CVE-2026-8065, CVE-2026-8066, CVE-2026-8067, CVE-2010-2965, CVE-2014-9195, and CVE-2023-46143.

These vulnerabilities permit unauthenticated remote attackers to upload arbitrary firmware, overwrite system files via directory traversal, or trigger device reboots, leading to potential operational disruption or unauthorized control of industrial hardware. Because these firmware versions are no longer maintained, Hitachi Energy explicitly advises upgrading to supported versions (12.7.8, 13.9.1, or later) to remediate these risks. Organizations relying on this equipment in critical energy sectors are at elevated risk if these devices remain exposed to network segments accessible by unauthorized entities.

Impact

Successful exploitation of these vulnerabilities can lead to a complete loss of device availability, unauthorized modification of industrial control logic, and compromise of system integrity. Given the deployment of RTU500 devices within the global energy sector, these issues pose a significant risk to operational continuity. An attacker achieving exploitation could effectively disable remote terminal units, potentially impacting downstream industrial processes and resulting in service outages.

Recommendation

  • Upgrade all affected RTU500 CMU firmware instances to version 12.7.8, 13.9.1, or the latest available supported release immediately.
  • Isolate EOL RTU500 hardware behind secure industrial firewalls to restrict inbound access to the web management interface and the WDB target agent debug service on UDP port 17185.
  • Implement defense-in-depth strategies, including network segmentation and monitoring for anomalous traffic directed at OT control assets.
  • Discontinue the use of firmware versions 11.x and earlier in production environments where security maintenance is required.

Immediate actions

Upgrade RTU500 CMU Firmware to version 12.7.8 or 13.9.1

OT Security 72h

Mitigations

Restrict access to web management and UDP port 17185 via network segmentation

immediate Network Operations

CVE-2026-8065, CVE-2026-8066, CVE-2010-2965