Executive Summary

CVE-2026-62649 is an unauthenticated remote denial-of-service in the Reyrolle 7SR5 web server, where a high volume of concurrent HTTP requests exhausts system resources and forces the entire device to crash and reboot. In a protection relay this is not a service outage in the IT sense, it is the temporary loss of the device that trips breakers on fault conditions, which means the substation runs without that protection element during the reboot window.

Technical Exposure Breakdown

The vulnerable component is the embedded web server on the Reyrolle 7SR5, which is stated to be affected across all versions below V2.70. The defect is a failure to properly limit or manage system resources when the server processes concurrent HTTP requests. This is a classic resource-exhaustion pattern on a constrained embedded platform: the HTTP handler accepts and queues connections faster than it can service or reclaim them, and the shared resource pool that the protection and communication tasks depend on is starved until the device faults and reboots.

The attack vector is network, and no authentication is required. An attacker who can reach TCP port 80 or 443 on the relay can generate the request volume needed to trigger the crash. There is no need for valid credentials, engineering software, or protocol-specific knowledge. Simple HTTP request flooding tooling is sufficient. The CVSS score is 7.5, consistent with an unauthenticated, network-reachable availability impact with no confidentiality or integrity component.

The condition that makes this exploitable is exposure of the management web interface. Reyrolle 7SR5 units are frequently commissioned with the web server enabled for configuration, diagnostics, and disturbance record retrieval. In flat substation LANs and poorly segmented process bus designs, that interface is reachable from far more of the network than it should be.

OT Impact and Compliance Risk

A protection relay that reboots is offline for its full restart cycle. During that window the associated feeder, transformer, or busbar zone has no functioning protection from that device. If a fault occurs while the relay is rebooting, backup protection with longer clearing times must operate, which increases equipment damage, arc-flash energy, and the size of the resulting outage. An attacker who times or sustains the DoS can hold a protection element down and turn a normal fault into a cascading event.

The physical criticality is why this rates attention beyond its numeric score. Under IEC 62443 this maps directly to loss of an essential function and to zone and conduit segmentation failures around the device. For North American electric utilities, an intentionally induced relay reboot touches NERC CIP availability and event-reporting obligations, and repeated or coordinated triggering may qualify as a reportable cyber security incident. Operators should also weigh this against their protection coordination studies, since those studies assume the relay is present and healthy.

Compensating Controls

Do not treat active scanning as a safe discovery method here. Probing the web server of a live protection relay can itself trigger the resource condition and brick or reboot the device you are trying to inventory. Identify affected units through passive asset inventory and configuration records instead.

Patch status for this advisory is not confirmed in available data. Validate any firmware update against your protection coordination and change-management process before field deployment, and treat network isolation as the primary control until then.

BreachSpider Intel

BreachSpider tracks CVE-2026-62649 and related protection-relay exposures across the ICS advisory stream so operators can prioritize isolation before exploitation, monitored through Intel by BreachSpider.