CVE Vulnerabilities

CVE-2026-1773

Incomplete List of Disallowed Inputs

Published: Feb 24, 2026 | Modified: Feb 27, 2026
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IEC 60870-5-104: Potential Denial of Service impact on reception of invalid U-format frame. Product is only affected if IEC 60870-5-104 bi-directional functionality is configured. Enabling secure communication following IEC 62351-3 does not remediate the vulnerability but mitigates the risk of exploitation.

Weakness

The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

Affected Software

NameVendorStart VersionEnd Version
Rtu540_firmwareHitachienergy12.7.1 (including)12.7.7 (including)
Rtu540_firmwareHitachienergy13.5.1 (including)13.5.4 (including)
Rtu540_firmwareHitachienergy13.6.1 (including)13.6.2 (including)
Rtu540_firmwareHitachienergy13.7.1 (including)13.7.8 (excluding)
Rtu540_firmwareHitachienergy13.8.1 (including)13.8.1 (including)

Potential Mitigations

References