Hitachi Energy urges upgrade of legacy RTU500 firmware after six critical CVEs

Customers with RTU500 CMU firmware 11.x or earlier must upgrade to 12.7.8, 13.9.1 or later immediately

cable network

Hitachi Energy issued a cybersecurity advisory recommending that all installations running RTU500 series CMU firmware versions 11.x and prior be upgraded to a supported release - specifically version 12.7.8, 13.9.1, or the latest available. The advisory cites six vulnerabilities (CVE-2026-8065, CVE-2026-8066, CVE-2026-8067, CVE-2010-2965, CVE-2014-9195, CVE-2023-46143) that collectively receive a CVSS v3 score of 9.8.

The reported flaws include missing authentication for critical functions, relative path traversal, missing and incorrect authorization, and a download-of-code-without-integrity-check issue. Exploitation could allow unauthenticated attackers to upload arbitrary firmware, overwrite files, trigger device reboots, execute arbitrary commands, or modify running applications, potentially compromising device integrity, availability, or safety.

Hitachi Energy notes that the vulnerabilities affect only end-of-life firmware versions; currently supported RTU500 releases are not impacted. The vendor's remediation guidance is limited to firmware replacement, as the legacy code is no longer receiving security updates.

CISA's accompanying recommendations stress defense-in-depth measures: isolate control-system networks behind firewalls, prevent direct internet exposure, employ VPNs for remote access, and enforce strict password and patch-management policies. Organizations are urged to conduct impact analyses and risk assessments before implementing any defensive changes.

Customers should contact Hitachi Energy service channels for upgrade assistance and consult the company's "Industrial Control Systems Cybersecurity Best Practices" documentation for additional hardening steps.

Keep reading