Junglewise Threat Intelligence

CVE-2026-62646: Siemens Reyrolle 7SR5 weak session identifier generation

CVE-2026-62646 · Severity: high · CVSS 7.4 · Published 2026-09-08

Technologies: Siemens Reyrolle 7SR5. Vendors: Siemens.

Executive brief

Siemens Reyrolle 7SR5 is a protection and automation device used in electrical substations to control critical infrastructure. A flaw in how the device generates session identifiers allows attackers to predict valid login tokens and bypass authentication without credentials, potentially granting unauthorized remote access to critical power system controls.

Technical details

The vulnerability (CVE-2026-62646) stems from insufficient entropy in the session identifier generation algorithm (CWE-331). An unauthenticated remote attacker can predict or brute-force session identifiers within a feasible number of attempts due to the low randomness of the token generation. This enables authentication bypass and unauthorized device access. No user interaction is required. Siemens has released a patch available in version 2.70 and later.

Affected products

  • Siemens Reyrolle 7SR5 All versions < V2.70

Timeline

  • 2026-09-08: disclosed

References

Related threats