Executive brief
Siemens Reyrolle 7SR5 is a protection and control device used in electrical substations. A vulnerability in its firmware-update mode allows an attacker with physical access to send malformed data over a proprietary protocol, causing memory corruption that can crash the device or enable arbitrary code execution, compromising protection functions in critical infrastructure.
Technical details
CVE-2026-62653 is a memory corruption vulnerability (CWE-120) in the input validation of Siemens Reyrolle 7SR5 versions before V2.70. The vulnerability exists in the proprietary communication protocol that is exposed when the device enters firmware-update mode. An unauthenticated attacker with physical access to the device can send improperly validated input that triggers memory corruption, resulting in a denial of service (crash) or potentially arbitrary code execution. The attack requires physical access and activation of the special firmware-update mode, but no authentication is required once that mode is entered. A patch is available in version 2.70 and later.
Affected products
- Siemens Reyrolle 7SR5 All versions < V2.70
Timeline
- 2026-09-08: disclosed
- 2026-09-08: patched: Update to V2.70 or later available