Executive brief
Reyrolle 7SR5 is an electrical substation protection and automation device that provides critical control functions for power grids. A vulnerability in its web interface exposes information that allows attackers to predict session IDs and bypass authentication, gaining full unauthorized access to device configuration and operations without requiring valid credentials.
Technical details
CVE-2026-62645 is an information disclosure vulnerability in Reyrolle 7SR5 web interface that exposes data enabling calculation of current and past session ID numbers. The vulnerability results from insufficient entropy in session identifier generation combined with information leakage through the web interface. An unauthenticated attacker on the network can access the web interface, extract exposed information, and derive valid session tokens to bypass authentication. This allows complete unauthorized access to device management and control functions. The vulnerability affects all versions before V2.70; the vendor has released a patch and recommends immediate update.
Affected products
- Siemens Reyrolle 7SR5 all versions before V2.70
Timeline
- 2026-09-08: disclosed
- 2026-09-08: patched: Update to V2.70 or later