Executive brief
Reyrolle 7SR5 is a protection and automation device used in electrical substations. An unauthenticated attacker can send a specially crafted HTTP request with an invalid URL length that causes an out-of-bounds memory write, crashing the device and denying legitimate access until it reboots.
Technical details
This is an out-of-bounds write vulnerability caused by improper validation of the URL component length in pre-authenticated HTTP messages. The vulnerable code does not check the URL length before appending additional data to it, resulting in a buffer overflow in memory. An unauthenticated remote attacker on the network can exploit this by sending a malformed HTTP request, triggering a crash and denial-of-service condition. A patch is available via update to version V2.70 or later.
Affected products
- Siemens Reyrolle 7SR5 All versions before V2.70
Timeline
- 2026-09-08: disclosed