Executive brief
Siemens Reyrolle 7SR5 is a protective relay device used in electrical substations to monitor and control power systems. An attacker with physical access to the device can activate a special maintenance mode using a key sequence during boot, then force the device to download and run unsigned code from a network server without verification. This allows arbitrary code execution on critical power infrastructure.
Technical details
CVE-2026-62654 is an insecure firmware update mechanism in the maintenance mode of Reyrolle 7SR5. The vulnerability is triggered by a physical key sequence during device boot that activates a special maintenance state. In this mode, the device fetches program code from a network server without cryptographic verification of authenticity or integrity. An attacker with physical access can exploit this to upload and execute arbitrary unsigned code with device privileges, compromising the relay's protective functions and potentially affecting substation operations. The fix is to update to version V2.70 or later.
Affected products
- Siemens Reyrolle 7SR5 All versions < V2.70
Timeline
- 2026-09-08: disclosed
- 2026-09-08: patched: Update to V2.70 or later