CVE-2026-62652
Deferred Deferred - Pending Action

Debug Symbols Disclosure in Reyrolle 7SR5 Firmware

Vulnerability report for CVE-2026-62652, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-10

Assigner: siemens-SADP

Description

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The device firmware contains binaries from which debugging symbols have not been removed. This could allow an unauthenticated attacker with access to the publicly available firmware update files to more easily reverse engineer the device's firmware, facilitating the identification of further vulnerabilities.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-10
Generated
2026-09-28
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
siemens reyrolle_7sr5 to 2.70 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-215 The product inserts sensitive information into debugging code, which could expose this information if the debugging code is not disabled in production.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Reyrolle 7SR5 devices running firmware versions below V2.70. The issue is that debugging symbols were not removed from the firmware binaries. This makes it easier for unauthenticated attackers to reverse engineer the firmware and potentially find additional vulnerabilities.

Detection Guidance

This vulnerability involves exposed debugging symbols in firmware binaries of Reyrolle 7SR5 devices. Detection requires analyzing firmware files for debugging symbols. Check firmware update files for symbols using tools like 'nm', 'objdump', or 'readelf' on binary files. Compare versions against V2.70 or later.

Impact Analysis

An attacker could exploit this to analyze the firmware more easily, which may lead to further attacks on the device. This could compromise the confidentiality or integrity of the device's operations if additional vulnerabilities are discovered and exploited.

Mitigation Strategies

Upgrade Reyrolle 7SR5 devices to firmware version V2.70 or later to remove debugging symbols. Ensure firmware files are obtained only from official Siemens sources. Restrict access to firmware files to authorized personnel only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-62652. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart