Junglewise Threat Intelligence

CVE-2026-9651: Schneider Electric RTU incorrect permission assignment in system files

CVE-2026-9651 · Severity: info · CVSS 6.7 · Published 2026-06-25

Vendors: Schneider Electric.

Executive brief

Schneider Electric industrial controllers used in power and automation systems contain a security flaw where sensitive system files are not properly protected. An attacker who already has high-level access to the device could read these files to obtain encrypted user passwords. This could allow the attacker to crack those passwords and gain further unauthorized access to the system, potentially disrupting operations.

Technical details

An Incorrect Permission Assignment (CWE-732) vulnerability exists in the firmware of Schneider Electric EasyLogic T150 and Saitel DP Remote Terminal Units (RTUs). The flaw resides in improperly protected system files that store sensitive authentication data. An attacker with local, high-privileged access (PR:H) can read these files to extract password hashes. These hashes can then be subjected to offline brute-force or dictionary attacks to recover plaintext credentials, leading to potential account compromise. The vulnerability is addressed in the latest security notices from Schneider Electric.

Affected products

  • Schneider Electric EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller Version 11.06.31 and prior
  • Schneider Electric Saitel DP Remote Terminal Unit & Controller Version 11.06.37 and prior

Timeline

  • 2026-06-25: disclosed
  • 2026-06-25: advisory

References

Related threats