CVE-2026-62654

MEDIUM

View CSAF Summary Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities. Siemens has released a new version for Reyrolle 7SR5 and recommends to update to the latest version. Th...

Affects 0 products across 1 vendor.

CVSS 3.16.8
CVSS v47.0
EPSS0.2%
Percentile5th
PatchUnknown
CVSS Vector — Plain English Requires physical access, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-494: CWE-494
Related Attack Patterns (CAPEC)
CAPEC-187 Malicious Automated Software Update via Redirection
via CWE-494
CAPEC-533 Malicious Manual Software Update
via CWE-494
CAPEC-538 Open-Source Library Manipulation
via CWE-494
CAPEC-657 Malicious Automated Software Update via Spoofing
via CWE-494
CAPEC-692 Spoof Version Control System Commit Metadata
via CWE-494
Show all 12

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

A medium severity vulnerability (CVE-2026-62654) affects the target system. A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A special maintenance mode can be activated via a physical key sequence during device boot, in which the device downloads and executes program code from a network server wit...

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-62654?
A medium severity vulnerability (CVE-2026-62654) affects the target system. A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A special maintenance mode can be activated via a physical key sequence during device boot, in which the device downloads and executes program code from a network server wit...
What is the CVSS score for CVE-2026-62654?
CVE-2026-62654 has CVSS 6.8 (Medium). Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.2%.
Is CVE-2026-62654 actively exploited?
No confirmed active exploitation of CVE-2026-62654 as of 2026-09-16.
How do I remediate CVE-2026-62654?
Apply vendor patches for CVE-2026-62654. Monitor Siemens advisories.
What systems are affected by CVE-2026-62654?
CVE-2026-62654 affects: Siemens.
Vulnerability Details
CVE IDCVE-2026-62654
CVSS VectorCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2026-09-08
Last Modified2026-09-15
ICS Relevance55%
Weakness (CWE)
SourceNVD
Official Description

View CSAF Summary Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities. Siemens has released a new version for Reyrolle 7SR5 and recommends to update to the latest version. The following versions of Siemens Reyrolle 7SR5 are affected: Reyrolle 7SR5 vers:intdot/<2.70 (CVE-2024-42384, CVE-2024-42385, CVE-2024-42386, CVE-2024-42391, CVE-2024-42392, CVE-2026-62645, CVE-2026-62646, CVE-2026-62647, CVE-2026-62648, CVE-2026-62649, CVE-2026-62650, CVE-2026-62652, CVE-2026-62653, CV

Source: NIST NVD / MITRE CVE Database

Affected Products
VendorProductFixed Version
Siemens &mdash; —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 20 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
Related CVEs affecting Siemens
CVE-2007-1917 10.0 Buffer overflow in the SYSTEM_CREATE_INSTANCE function in the SAP RFC Library... CVE-2026-56451 10.0 A vulnerability has been identified in Opcenter X (All versions < V2604). Aff... CVE-2008-6916 10.0 Siemens SpeedStream 5200 with NetPort Software 1.1 allows remote attackers to... CVE-2008-6993 10.0 Siemens Gigaset WLAN Camera 1.27 has an insecure default password, which allo... CVE-2011-4514 10.0 The TELNET daemon in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC...
View all Siemens CVEs →

Monitoring Siemens Vulnerabilities in Your Environment?

BreachSpider tracks every Siemens CVE and maps them to your ICS assets automatically. Get email or webhook alerts when a newly published Siemens vulnerability matches your assets.

Create a free account →