Junglewise Threat Intelligence

CVE-2026-1773: Hitachi Energy RTU500 Denial of Service in IEC 60870-5-104

CVE-2026-1773 · Severity: high · CVSS 7.5 · Published 2026-02-24

Vendors: Hitachi Energy.

Executive brief

A vulnerability exists in Hitachi Energy RTU500 series remote terminal units, which are used to monitor and control equipment in electrical substations and industrial automation. An attacker could remotely crash the device by sending a specially crafted network packet, leading to a loss of monitoring and control capabilities. This issue specifically affects devices configured with bi-directional communication using the IEC 60870-5-104 protocol.

Technical details

The vulnerability is classified as an Incomplete List of Disallowed Inputs (CWE-184) within the IEC 60870-5-104 protocol implementation of the RTU500 series. It is triggered upon the reception of a specially crafted, invalid U-format frame. Exploitation is only possible if the IEC 60870-5-104 bi-directional functionality is configured. A remote, unauthenticated attacker can exploit this over the network to cause a Denial of Service (DoS) condition. While implementing secure communication per IEC 62351-3 mitigates the risk by requiring authentication, it does not remediate the underlying parsing flaw.

Affected products

  • Hitachi Energy RTU520 firmware 12.7.1 - 12.7.7, 13.5.1 - 13.5.4, 13.6.1 - 13.6.2, 13.7.1 - 13.7.7, 13.8.1
  • Hitachi Energy RTU530 firmware 12.7.1 - 12.7.7, 13.5.1 - 13.5.4, 13.6.1 - 13.6.2, 13.7.1 - 13.7.7, 13.8.1
  • Hitachi Energy RTU540 firmware 12.7.1 - 12.7.7, 13.5.1 - 13.5.4, 13.6.1 - 13.6.2, 13.7.1 - 13.7.7, 13.8.1
  • Hitachi Energy RTU560 firmware 12.7.1 - 12.7.7, 13.5.1 - 13.5.4, 13.6.1 - 13.6.2, 13.7.1 - 13.7.7, 13.8.1

Timeline

  • 2026-02-24: disclosed
  • 2026-02-24: advisory

References