CVE-2026-8065 — Hitachi Energy RTU500 Unauthenticated Firmware Update Bypass
September 29, 2026 · 581 views
Hitachi Energy RTU500 Series CMU firmware: CWE-306 missing authentication on the firmware update HTTP endpoint — unauthenticated arbitrary firmware upload via crafted POST (CVSS 3.1 9.1 Critical, IoT/OT). Affected CMU lines include 9.0 and 12.0 per vendor advisory. Python PoC: RTU500 fingerprint, path probe, lab-safe upload test, check + mass exploit -j. Authorized OT/lab only.
Description
Overview
CVE-2026-8065 — Hitachi Energy RTU500 Series CMU Firmware — authentication bypass (CWE-306) on the firmware update HTTP endpoint. CVSS 3.1 9.1 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).
| | | |---|---| | Product | RTU500 remote terminal unit (substation / grid OT) | | Issue | Unauthenticated access to firmware update function | | Impact | Arbitrary firmware upload → integrity / availability of field RTU | | CWE | CWE-306 Missing Authentication for Critical Function | | Distinct from | CVE-2024-2617 (authenticated bypass of secure update when disabled) |
Vendor (CNA) text: an unauthenticated attacker can upload arbitrary firmware through a crafted POST to the firmware update endpoint.
Affected (vendor): RTU500 CMU firmware 9.0 and 12.0 version lines — follow Hitachi Energy advisory for 13.8.2+ patch guidance and exact fixed builds.
PoC page: https://pocbit.org/pocs/cve-2026-8065
GitHub: murrez/CVE-2026-8065
Bundled tool (Python 3)
Download poc.py from this page (View exploit code).
pip install -r requirements.txt
python poc.py --lab
python poc.py -u https://192.168.1.10 --mode check
python poc.py -u https://192.168.1.10 --mode exploit --dry-run
python poc.py -u https://192.168.1.10 --mode exploit
python poc.py -u https://192.168.1.10 --mode exploit --firmware-paths /api/firmware/update
python poc.py --list targets.example.txt --mode check -j 40
python poc.py --list hits.txt --mode exploit -j 8 --timeout 25
| Mode | Behavior |
|------|----------|
| check | Multi-port HTTP(S), RTU500 HTML markers, CMU version regex, GET on firmware path candidates |
| exploit | POST multipart probe blob (POCBIT-8065-FW-PROBE) without session; exploited on 2xx + accept heuristics |
| mass | --list + -j → hits.txt, exploited.txt |
| --dry-run | Exploit: GET probe only, no POST |
| --lab | Local mock RTU500 sanity check |
| --force | Exploit without strong RTU500 HTML fingerprint |
| --firmware-paths | Comma-separated URI override when vendor publishes exact path |
Default exploit payload is not a valid CMU flash image — marker + padding for detection only. Never run exploit mode against live grid equipment without isolation and vendor coordination.
Check vs exploit expectations
Bulk check defaults are tuned for FOFA-scale lists (short timeouts, limited GET per target). Check hit ≠ confirmed RTU: pages with only Hitachi Energy branding may be vendor_branding_only false positives. Strong fingerprints include rtu500, rtutil500, CMU firmware markers before treating exploit results as meaningful.
Default firmware path candidates
PoC rotates GET/POST paths including:
/api/firmware/update,/api/firmware/upload,/api/v1/firmware/update/firmware/update,/firmware/upload,/ws/firmware/update/CMU/firmware/upload,/ConfigurationManagement/Firmware/configuration/management/firmware,/FileUpload/Firmware/scripts/firmwareUpload,/cgi-bin/firmware,/admin/firmware/upload
When Hitachi publishes the exact URI, set --firmware-paths to that path only.
Mitigation
- Apply Hitachi Energy security advisory / CMU firmware per publisher.hitachienergy.com (CVE-2026-8065).
- Network segmentation — do not expose RTU web UI to the internet; jump host + MFA.
- Monitor anomalous firmware POST and configuration changes.
- Align with IEC 62351-3 and secure-update policies (see CVE-2024-2617 hardening context).
Hunting (examples)
title="RTU500" || body="RTU500" || body="Configuration Management"
body="Hitachi Energy" && (body="RTU" || body="CMU")
body="RTUtil500" || body="rtutil500"
OT networks may be absent from internet scanners — use CMMS / IP plans / VPN inventory for targets.txt.
Legal and ethical use
Authorized substation or isolated lab testing only. Unauthorized firmware manipulation on OT devices may violate law and grid safety rules.
References
- NVD — CVE-2026-8065
- PoCbit catalog
- GitHub PoC — CVE-2026-8065
- CISA ICS advisories for RTU500 (related issues: IEC104 DoS, web info disclosure)
Related PoCs
Same platform, vendor, or tags — explore more write-ups on Pocbit.
- IoT / OTCVE-2026-100740high
CVE-2026-100740 — D-Link DIR-895L L2TP Host Name AVP Out-of-Bounds Write
Out-of-bounds write (CWE-787 / CWE-119) in D-Link DIR-895L firmware A1_102b07 L2TP tunnel_set_params() — Host Name AVP length clamped to 127 but NUL written at peer_hostname[len+1] on a 128-byte buffer. Remote attack over UDP 1701 when L2TP is active. PoC fingerprints the router, probes UDP 1701, optional lab-only --oob-send trigger. No vendor fix listed in NVD at publication.
- IoT / OTCVE-2026-13249critical
CVE-2026-13249 — Honeywell PD45 Unauthenticated File Upload (RCE)
Unauthenticated arbitrary file upload on Honeywell PD45 Industrial Printer HTTPS web admin (firmware F10.19.010040 through before F10.22.030745) — CWE-306/434/78, CVSS 9.8 Critical. Attacker-controlled files may execute on the device. Fixed in firmware F10.22.030745.
- IoT / OTCVE-2026-93958critical
CVE-2026-93958 — D-Link R95 BE9500 DHMAPI NTPServer Root Command Injection
Authenticated OS command injection (CWE-77/78) in D-Link R95 BE9500 firmware BE9500_1.00.16 (1.01B06): DHMAPI SetTimeSettings stores NTPServer unsanitized; UCI sync runs shell with backticks as root. Requires admin Login + API-AUTH HMAC (port 18443/443). CVSS 9.1 Critical. Python PoC: check/exploit, mass bulk -j, colored CLI.
- JoomlaCVE-2026-76570critical
CVE-2026-76570 — Joomla JCTables (com_jctables) Unauthenticated SQL Read/Write via JSON API
Joomcode JCTables 1.0.0–1.20.0: unauthenticated front-end JSON tasks (getdatarow, getrow) concatenate table/column names into SQL with broken escaping — arbitrary DB read/write (CWE-89/CWE-862). CVSS 4.0 10.0 Critical (AT:N). Fixed in 1.21.1+. Python PoC proves user row read (POCBIT-76570-OK); check + exploit + mass -j.