Hitachi Energy RTU500
CISA warned of multiple vulnerabilities in Hitachi Energy RTU500 firmware that could disrupt availability and, in some cases, confidentiality or integrity.
Intelligence analysis by GPT-5.4 Mini
CISA issued an ICS advisory for Hitachi Energy RTU500, covering several CVEs in CMU firmware versions through 13.8.1. The main risk is denial of service, with fixes available in newer firmware releases.
CISA found bugs in a control-system device that could make it crash, like a phone app freezing after opening a bad file. The safest fix is to install the newer software version the maker released.
Analysis
What CISA reported
CISA says Hitachi Energy is aware of vulnerabilities affecting RTU500 product versions listed in the advisory. The agency characterizes the main impact as loss of availability, with possible secondary effects on confidentiality and integrity.
The advisory covers several firmware ranges for the RTU500 series CMU, including versions 12.7.1 through 12.7.7, 13.5.1 through 13.5.4, 13.6.1 through 13.6.3, 13.7.1 through 13.7.8, and 13.8.1. The listed issues include CVE-2025-69421, CVE-2026-24515, CVE-2026-25210, CVE-2026-32776, CVE-2026-32777, CVE-2026-32778, and CVE-2026-8479.
Several of the flaws are described as denial-of-service conditions. One involves a malformed PKCS#12 file that can trigger a null pointer dereference and crash an application processing certificates. Another affects libexpat before 2.7.4 and can cause a denial of service when IEC 61850 functionality is configured. A third issue involves an integer overflow in libexpat that can primarily disrupt service and, according to the advisory, potentially affect confidentiality and integrity as well.
CISA says the product is affected only under certain configurations for some issues, including privileged upload of a malformed PKCS#12 certificate through the web interface, PKI client functionality, or IEC 61850 being enabled. The recommended fix is to update CMU firmware to 13.8.2, or to 13.7.9 when that becomes available, and to follow the vendor's mitigation guidance.
Key points
- CISA issued an advisory for Hitachi Energy RTU500 firmware vulnerabilities.
- The main impact is denial of service, with possible secondary effects on confidentiality and integrity.
- Affected CMU firmware versions include several ranges up to 13.8.1.
- CISA recommends updating to CMU Firmware 13.8.2, or 13.7.9 when available.
- Some issues only matter when specific features such as IEC 61850 or PKI client support are enabled.
Hitachi Energy has provided firmware updates, which gives operators a clear path to reduce exposure. Because several issues are tied to specific configurations, sites that are not using those features may be able to lower risk quickly while planning upgrades.
If unpatched, the bugs could let a bad file or malformed certificate knock parts of the system offline. Sites using IEC 61850 or certificate-related features face a more direct path to disruption if attackers can reach the affected interfaces.



