Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-17539

Quick assessment

Affected
Hitachi Energy RTU500 series CMU firmware
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

RTU500 存在一个漏洞:在高负载场景下(例如以较短的时间间隔发送 GI 请求),可能导致增强型消息队列最后一个条目发生空指针解引用。这会引发 BCI_IEC104 的致命写错误,导致连接中断并重启,最终造成 IEC 60870-5-104 双向通信的服务中断。

CVSS 5.9 · Medium EPSS 0.35% · P28

Possible ATT&CK Techniques 1 AI

T1014 · Rootkit

Affected Version Matrix 5

VendorProduct Version RangeStatus
Hitachi Energy RTU500 series CMU firmware 12.7.1≤ 12.7.7 affected
13.5.1≤ 13.5.4 affected
13.6.1≤ 13.6.3 affected
13.7.1≤ 13.7.8 affected
13.8.1≤ 13.8.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-17539

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
RTU500 has a vulnerability, where high-load scenarios, such as sending GI requests at short intervals, may cause a NULL pointer dereference in the last entry of the enhanced message queue. This can cause a BCI_IEC104 fatal write error, resulting in connection interruption and restart, and ultimately a denial of service for bidirectional IEC 60870-5-104 communication.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
空指针解引用
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Hitachi Energy RTU500 series CMU firmware 12.7.1 ~ 12.7.7 -

II. Public POCs for CVE-2026-17539

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-17539

登录查看更多情报信息。

Vendor Advisories for CVE-2026-17539 (1)

Same Patch Batch · Hitachi Energy · 2026-09-03 · 4 CVEs total

CVE-2026-9854 8.5 HIGH SYS600 RBAC权限提升至Windows管理员漏洞
CVE-2026-9853 8.5 HIGH SYS600 认证缺失致对象越权读写漏洞
CVE-2026-9852 4.6 MEDIUM SYS600 CSV注入漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-17539

No comments yet


Leave a comment