CVE-2026-62654
Received Received - Intake

Reyrolle 7SR5 Physical Key Sequence Code Execution

Vulnerability report for CVE-2026-62654, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: siemens-SADP

Description

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A special maintenance mode can be activated via a physical key sequence during device boot, in which the device downloads and executes program code from a network server without verifying its authenticity or integrity. This could allow an attacker with physical access to the device to upload and execute arbitrary, unsigned code.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-28
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
siemens reyrolle_7sr5 to 2.70 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-494 The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Reyrolle 7SR5 devices running versions below V2.70. It allows activation of a special maintenance mode via a physical key sequence during boot. In this mode, the device can download and execute program code from a network server without checking if the code is authentic or has been tampered with. An attacker with physical access could exploit this to upload and run arbitrary, unsigned code on the device.

Detection Guidance

This vulnerability requires physical access to the device during boot to activate maintenance mode. Detection primarily involves monitoring for unauthorized physical access or unusual boot sequences. Check device logs for unexpected maintenance mode activations or network downloads during boot.

Impact Analysis

If you use Reyrolle 7SR5 devices with versions below V2.70, an attacker with physical access could compromise the device. This may lead to unauthorized code execution, potentially disrupting operations, stealing sensitive data, or causing physical damage to connected systems. The impact depends on the device's role in your infrastructure.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Failure to address it may result in legal penalties, loss of certification, or reputational damage due to compromised data integrity or confidentiality.

Mitigation Strategies

Upgrade Reyrolle 7SR5 devices to version V2.70 or later to address the vulnerability. Ensure physical access to devices is restricted to authorized personnel only. Monitor device boot sequences for unauthorized maintenance mode activations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-62654. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart