Executive Summary
CVE-2026-62649 is an unauthenticated remote denial-of-service in the Reyrolle 7SR5 web server, where a high volume of concurrent HTTP requests exhausts system resources and forces the entire device to crash and reboot. In a protection relay this is not a service outage in the IT sense, it is the temporary loss of the device that trips breakers on fault conditions, which means the substation runs without that protection element during the reboot window.
Technical Exposure Breakdown
The vulnerable component is the embedded web server on the Reyrolle 7SR5, which is stated to be affected across all versions below V2.70. The defect is a failure to properly limit or manage system resources when the server processes concurrent HTTP requests. This is a classic resource-exhaustion pattern on a constrained embedded platform: the HTTP handler accepts and queues connections faster than it can service or reclaim them, and the shared resource pool that the protection and communication tasks depend on is starved until the device faults and reboots.
The attack vector is network, and no authentication is required. An attacker who can reach TCP port 80 or 443 on the relay can generate the request volume needed to trigger the crash. There is no need for valid credentials, engineering software, or protocol-specific knowledge. Simple HTTP request flooding tooling is sufficient. The CVSS score is 7.5, consistent with an unauthenticated, network-reachable availability impact with no confidentiality or integrity component.
The condition that makes this exploitable is exposure of the management web interface. Reyrolle 7SR5 units are frequently commissioned with the web server enabled for configuration, diagnostics, and disturbance record retrieval. In flat substation LANs and poorly segmented process bus designs, that interface is reachable from far more of the network than it should be.
OT Impact and Compliance Risk
A protection relay that reboots is offline for its full restart cycle. During that window the associated feeder, transformer, or busbar zone has no functioning protection from that device. If a fault occurs while the relay is rebooting, backup protection with longer clearing times must operate, which increases equipment damage, arc-flash energy, and the size of the resulting outage. An attacker who times or sustains the DoS can hold a protection element down and turn a normal fault into a cascading event.
The physical criticality is why this rates attention beyond its numeric score. Under IEC 62443 this maps directly to loss of an essential function and to zone and conduit segmentation failures around the device. For North American electric utilities, an intentionally induced relay reboot touches NERC CIP availability and event-reporting obligations, and repeated or coordinated triggering may qualify as a reportable cyber security incident. Operators should also weigh this against their protection coordination studies, since those studies assume the relay is present and healthy.
Compensating Controls
Do not treat active scanning as a safe discovery method here. Probing the web server of a live protection relay can itself trigger the resource condition and brick or reboot the device you are trying to inventory. Identify affected units through passive asset inventory and configuration records instead.
- Disable the web server on any 7SR5 unit that does not require it for active operation, and re-enable only for the duration of a maintenance session.
- Restrict TCP 80 and 443 to a single hardened engineering workstation or jump host using access control lists on the substation switch or an inline firewall. The web interface should never be reachable from the general control network.
- Deploy a virtual patch at the segment boundary. Rate-limit inbound HTTP connections per source and enforce a low concurrent-connection ceiling toward relay IP ranges, since legitimate engineering access is single-user and low-volume.
- A Suricata concept: alert and then drop when new HTTP connection establishment toward relay host addresses exceeds a tight threshold per source over a short window, and threshold on incomplete or half-open sessions that indicate flood behavior rather than an engineer opening a page.
- Monitor relays for unexpected reboots and correlate reboot timestamps with network flow spikes to detect exploitation attempts against units you cannot yet isolate.
Patch status for this advisory is not confirmed in available data. Validate any firmware update against your protection coordination and change-management process before field deployment, and treat network isolation as the primary control until then.
BreachSpider Intel
BreachSpider tracks CVE-2026-62649 and related protection-relay exposures across the ICS advisory stream so operators can prioritize isolation before exploitation, monitored through Intel by BreachSpider.