CVE-2026-62648
Received Received - Intake

Out-of-Bounds Write in Reyrolle 7SR5 Firmware

Vulnerability report for CVE-2026-62648, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: siemens-SADP

Description

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The length of the URL component contained in pre-authenticated HTTP messages is not properly validated before appending additional data to it, resulting in an out-of-bounds write condition in memory. This could allow an unauthenticated remote attacker to crash the affected device, causing a reboot and resulting in a denial-of-service condition.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-28
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
siemens reyrolle_7sr5 to 2.70 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Reyrolle 7SR5 devices running versions before V2.70. It involves improper validation of URL length in pre-authenticated HTTP messages, leading to an out-of-bounds write in memory. An unauthenticated remote attacker could exploit this to crash the device, causing a reboot and denial-of-service.

Detection Guidance

Detecting this vulnerability requires monitoring for unusual HTTP requests targeting Reyrolle 7SR5 devices with URLs exceeding normal length limits. Inspect network traffic for HTTP GET/POST requests with abnormally long URLs directed at devices running versions below V2.70. Use packet capture tools like tcpdump or Wireshark to analyze HTTP headers and URL lengths.

Impact Analysis

If you use Reyrolle 7SR5 devices with versions below V2.70, an attacker could remotely crash your device, disrupting operations. This may lead to downtime, loss of control over critical systems, and potential safety risks depending on the device's role in your infrastructure.

Compliance Impact

This vulnerability could impact compliance by causing unplanned downtime or loss of control over systems, potentially violating availability requirements in GDPR or HIPAA. However, the CVE does not specify direct compliance impacts; mitigation is recommended to avoid disruptions.

Mitigation Strategies

Immediately update all Reyrolle 7SR5 devices to version V2.70 or later. If updating is not immediately possible, isolate affected devices from untrusted networks by placing them behind firewalls or in isolated VLANs. Monitor device logs for crashes or reboots that may indicate exploitation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-62648. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart