CVE-2026-8066
Received Received - Intake

Directory Traversal in Hitachi Energy RTU500 File Upload

Vulnerability report for CVE-2026-8066, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Hitachi Energy

Description

A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 allows an unauthenticated attacker to write or overwrite arbitrary files on the device file system. Depending on the files affected, successful exploitation could result in unauthorized modification of device data or disruption of the device’s intended operation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hitachi_energy rtu500 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-23 The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a directory traversal vulnerability in Hitachi Energy RTU500's file upload feature. It allows an unauthenticated attacker to write or overwrite arbitrary files on the device's file system. This could lead to unauthorized changes in device data or disrupt the device's normal operation.

Impact Analysis

An attacker could exploit this to modify critical device files, potentially causing system failures, data corruption, or unauthorized access to device functions. This may lead to operational disruptions or loss of control over the RTU500 device.

Compliance Impact

This vulnerability could lead to unauthorized file modifications on the device, potentially compromising sensitive data integrity. For GDPR, this may result in unauthorized access or processing of personal data, violating principles of data protection and security. For HIPAA, it could allow unauthorized changes to protected health information, risking compliance with integrity and confidentiality requirements.

Mitigation Strategies

Disable or restrict file upload functionality in Hitachi Energy RTU500 devices if not required. Apply vendor patches or updates as soon as they become available. Implement network segmentation to limit exposure of vulnerable devices. Monitor network traffic for unusual file upload patterns or unauthorized file modifications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-8066. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart