Junglewise Threat Intelligence

CVE-2026-17539: Hitachi Energy RTU500 NULL pointer dereference in IEC 104 messaging

CVE-2026-17539 · Severity: medium · CVSS 5.9 · Published 2026-09-03

Vendors: Hitachi Energy.

Executive brief

The Hitachi Energy RTU500 is a remote terminal unit used in electrical grid operations to manage power distribution and control equipment. A vulnerability in its IEC 60870-5-104 communication protocol handler can crash the device under high-load conditions, causing communication to fail and requiring manual restart, which disrupts grid monitoring and control operations.

Technical details

The vulnerability is a NULL pointer dereference in the enhanced message queue's last entry handler within the BCI_IEC104 component. When rapid GI (general interrogation) requests are sent at short intervals, the high-load scenario triggers improper memory management that results in a NULL pointer access. This causes a fatal write error in the IEC 104 bidirectional communication, forcing connection interruption and device restart. An attacker with network access to send IEC 104 commands could trigger this denial of service condition without requiring authentication.

Affected products

  • Hitachi Energy RTU500 <UNKNOWN>

Timeline

  • 2026-09-03: disclosed

References