{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/wind-river/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:rockwellautomation:1756-enbt\\/a_firmware:3.2.6:*:*:*:*:*:*:*","cpe:2.3:o:rockwellautomation:1756-enbt\\/a_firmware:3.6.1:*:*:*:*:*:*:*","cpe:2.3:o:windriver:vxworks:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-8066"},{"cvss":6.5,"id":"CVE-2026-8067"},{"cvss":9.8,"id":"CVE-2010-2965"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["RTU500 series CMU Firmware (\u003c= 11.x)","VxWorks (6.x, 5.x and earlier)"],"_cs_severities":["critical"],"_cs_tags":["ics","energy","ot-security","vulnerability-management"],"_cs_type":"advisory","_cs_vendors":["Hitachi Energy","Wind River"],"content_html":"\u003cp\u003eHitachi Energy has issued an advisory regarding multiple security vulnerabilities affecting legacy, end-of-life (EOL) RTU500 CMU firmware versions 11.x and earlier. These firmware versions, developed under historical industry standards, lack modern security controls such as robust authentication, encrypted communications, and integrity checks. Researchers reported that these legacy systems are susceptible to several high-severity flaws, including CVE-2026-8065, CVE-2026-8066, CVE-2026-8067, CVE-2010-2965, CVE-2014-9195, and CVE-2023-46143.\u003c/p\u003e\n\u003cp\u003eThese vulnerabilities permit unauthenticated remote attackers to upload arbitrary firmware, overwrite system files via directory traversal, or trigger device reboots, leading to potential operational disruption or unauthorized control of industrial hardware. Because these firmware versions are no longer maintained, Hitachi Energy explicitly advises upgrading to supported versions (12.7.8, 13.9.1, or later) to remediate these risks. Organizations relying on this equipment in critical energy sectors are at elevated risk if these devices remain exposed to network segments accessible by unauthorized entities.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities can lead to a complete loss of device availability, unauthorized modification of industrial control logic, and compromise of system integrity. Given the deployment of RTU500 devices within the global energy sector, these issues pose a significant risk to operational continuity. An attacker achieving exploitation could effectively disable remote terminal units, potentially impacting downstream industrial processes and resulting in service outages.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all affected RTU500 CMU firmware instances to version 12.7.8, 13.9.1, or the latest available supported release immediately.\u003c/li\u003e\n\u003cli\u003eIsolate EOL RTU500 hardware behind secure industrial firewalls to restrict inbound access to the web management interface and the WDB target agent debug service on UDP port 17185.\u003c/li\u003e\n\u003cli\u003eImplement defense-in-depth strategies, including network segmentation and monitoring for anomalous traffic directed at OT control assets.\u003c/li\u003e\n\u003cli\u003eDiscontinue the use of firmware versions 11.x and earlier in production environments where security maintenance is required.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-06T17:12:25Z","date_published":"2026-10-06T17:12:25Z","id":"https://feed.craftedsignal.io/briefs/2026-10-hitachi-rtu500/","summary":"End-of-life Hitachi Energy RTU500 CMU firmware versions 11.x and prior are susceptible to multiple critical vulnerabilities, including authentication bypass and path traversal, which could allow remote attackers to compromise device integrity or disrupt industrial control operations.","title":"Critical Vulnerabilities in End-of-Life Hitachi Energy RTU500 Firmware","url":"https://feed.craftedsignal.io/briefs/2026-10-hitachi-rtu500/"},{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["VxWorks 7","VxWorks"],"_cs_severities":["high"],"_cs_tags":["vulnerability","embedded-security","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":["Wind River"],"content_html":"\u003cp\u003eWind River has identified multiple security vulnerabilities affecting VxWorks 7, a widely used real-time operating system (RTOS) in embedded devices, industrial control systems, and network infrastructure. These vulnerabilities can be exploited by a local attacker to disrupt service availability through denial-of-service (DoS) conditions, execute arbitrary code with elevated privileges, or perform unauthorized disclosure and manipulation of sensitive system data. Given the pervasive use of VxWorks in critical infrastructure and embedded systems, successful exploitation could lead to significant operational disruptions. Defenders should monitor for vendor updates and patches addressing these specific vulnerabilities as documented by Wind River's security advisories.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities may lead to a complete denial of service for critical embedded systems, unauthorized remote or local code execution, and data corruption or exposure. These risks are particularly acute for organizations operating within critical infrastructure, medical device manufacturing, and industrial automation sectors that rely on VxWorks 7 for operational stability.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification of devices running VxWorks 7 within the organization's asset inventory. Verify current firmware versions against the official Wind River security updates and apply relevant patches or mitigations provided by the vendor. Ensure that physical and local access controls for devices running VxWorks are strictly enforced to minimize the local access vector identified in this advisory.\u003c/p\u003e\n","date_modified":"2026-10-02T14:21:25Z","date_published":"2026-09-29T22:18:08Z","id":"https://feed.craftedsignal.io/briefs/2026-09-wind-river-vxworks-vulnerabilities/","summary":"Multiple vulnerabilities in Wind River VxWorks 7 allow a local attacker to perform denial-of-service attacks, potentially execute arbitrary code, and disclose or manipulate sensitive data.","title":"Multiple Vulnerabilities in Wind River VxWorks 7","url":"https://feed.craftedsignal.io/briefs/2026-09-wind-river-vxworks-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Wind River","version":"https://jsonfeed.org/version/1.1"}