Executive brief
Reyrolle 7SR5 is a protection and control device used in electrical substations and critical power infrastructure. A flaw in the web-based management interface allows an authenticated user with low-level privileges to escalate to administrative access by bypassing role-based access controls, potentially enabling an attacker to take full control of the device and disrupt power grid operations.
Technical details
The vulnerability exists in the web-based management interface where server-side authorization checks are not properly enforced, allowing role-based access control (RBAC) restrictions to be bypassed through manipulation of request data. An authenticated, low-privileged remote attacker can exploit this flaw to escalate privileges to an administrative level without requiring additional credentials or user interaction. The vulnerability affects all versions of Reyrolle 7SR5 prior to V2.70, and Siemens has released V2.70 as the fixed version.
Affected products
- Siemens Reyrolle 7SR5 All versions < V2.70
Timeline
- 2026-09-08: disclosed