CVE-2026-1772
published 2026-02-24CVE-2026-1772: RTU500 web interface: An unprivileged user can read user management information. The information cannot be accessed via the RTU500 web user interface but…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.26%
18.1th percentile
RTU500 web interface: An unprivileged user can read user management information. The information cannot be accessed via the RTU500 web user interface but requires further tools like browser development utilities to access them without required privileges.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hitachi_energy | rtu500_series_cmu_firmware | — | — |
| hitachi_energy | rtu500_series_cmu_firmware | 12.7.1 – 12.7.7 | — |
| hitachi_energy | rtu500_series_cmu_firmware | 13.5.1 – 13.5.4 | — |
| hitachi_energy | rtu500_series_cmu_firmware | 13.6.1 – 13.6.2 | — |
| hitachi_energy | rtu500_series_cmu_firmware | 13.7.1 – 13.7.7 | — |
| hitachienergy | rtu520_firmware | — | — |
| hitachienergy | rtu520_firmware | 12.7.1 – 12.7.7 | — |
| hitachienergy | rtu520_firmware | 13.5.1 – 13.5.4 | — |
| hitachienergy | rtu520_firmware | 13.6.1 – 13.6.2 | — |
| hitachienergy | rtu520_firmware | >= 13.7.1 < 13.7.8 | 13.7.8 |
| hitachienergy | rtu530_firmware | — | — |
| hitachienergy | rtu530_firmware | 12.7.1 – 12.7.7 | — |
| hitachienergy | rtu530_firmware | 13.5.1 – 13.5.4 | — |
| hitachienergy | rtu530_firmware | 13.6.1 – 13.6.2 | — |
| hitachienergy | rtu530_firmware | >= 13.7.1 < 13.7.8 | 13.7.8 |
| hitachienergy | rtu540_firmware | — | — |
| hitachienergy | rtu540_firmware | 12.7.1 – 12.7.7 | — |
| hitachienergy | rtu540_firmware | 13.5.1 – 13.5.4 | — |
| hitachienergy | rtu540_firmware | 13.6.1 – 13.6.2 | — |
| hitachienergy | rtu540_firmware | >= 13.7.1 < 13.7.8 | 13.7.8 |
| hitachienergy | rtu560_firmware | — | — |
| hitachienergy | rtu560_firmware | 12.7.1 – 12.7.7 | — |
| hitachienergy | rtu560_firmware | 13.5.1 – 13.5.4 | — |
| hitachienergy | rtu560_firmware | 13.6.1 – 13.6.2 | — |
| hitachienergy | rtu560_firmware | >= 13.7.1 < 13.7.8 | 13.7.8 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Hitachi Energy RTU500 Product
cisa_ics·2026-03-03·CVSS 5.3
[MEDIUM] Hitachi Energy RTU500 Product
ICS Advisory
##
Hitachi Energy RTU500 Product
Release DateMarch 03, 2026
Alert CodeICSA-26-062-03
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
Hitachi Energy is aware of vulnerabilities that affect RTU500 product versions listed in this document. Successful exploitation of these vulnerabilities can result in the exposure of low-value user management information and device outage. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.
The following versions of Hitachi Energy RTU500 Product are affected:
- RTU500 series CMU Firmware vers:RTU500_series_CMU_Firmware/>=12.7.1|=13.5.1|=13.6.1|=13.7.1|<=13.7.7, 13.8.1
CVSS
Vendor
Equipment
Vulnerabilities
|
GHSA
GHSA-pwpc-5pp8-7qw9: RTU500 web interface: An unprivileged user can read user management information
ghsa_unreviewed·2026-02-24
CVE-2026-1772 [MEDIUM] CWE-280 GHSA-pwpc-5pp8-7qw9: RTU500 web interface: An unprivileged user can read user management information
RTU500 web interface: An unprivileged user can read user management information. The information cannot be accessed via the RTU500 web user interface but requires further tools like browser development utilities to access them without required privileges.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-02-24
Published