Executive Summary

CVE-2026-62650 is a server-side authorization flaw in the web-based management interface of Siemens Reyrolle 7SR5 protection relays (all versions before V2.70) that lets an authenticated low-privilege remote attacker manipulate request data to bypass role-based access control and gain administrative rights. Because these devices provide protection functions for power distribution and transmission assets, a privilege escalation on the relay places direct control of trip logic, protection settings, and configuration in the hands of an attacker.

Technical Exposure Breakdown

The defect sits in the authorization layer of the device web interface. Authentication is enforced, but the server does not consistently re-validate the caller's role against the requested action. The advisory characterizes this as authorization checks that are not properly enforced, allowing RBAC restrictions to be bypassed through manipulation of request data. In practical terms, a session that logged in with a read-only or operator-tier account can craft or modify requests referencing privileged endpoints or parameters, and the server processes them as though an administrator issued them.

This is a classic broken access control pattern where the client-supplied role indicator or resource identifier is trusted rather than the server-side session context. The attack precondition is low: valid low-privilege credentials and network reachability to the web interface. No memory corruption, no chained exploit, and no physical access are described. The CVSS score of 8.8 reflects that low barrier combined with a full compromise of confidentiality, integrity, and availability once escalation succeeds.

The key detail for defenders is that this attacker is already inside the trust boundary. Shared operator accounts, default engineering credentials, and contractor logins that were never rotated all become escalation paths. On a protection relay, an administrative session is the difference between reading a setting and changing the pickup threshold that decides whether a fault trips a breaker.

OT Impact and Compliance Risk

Reyrolle 7SR5 devices sit at the protection layer of substation and distribution automation. An attacker with administrative access can alter protection setpoints, disable elements, modify trip characteristics, or push configuration that leaves feeders unprotected during a fault. The physical outcome ranges from nuisance trips and unnecessary outages to suppressed protection that allows equipment damage during an actual fault condition. This is not data theft, it is manipulation of the logic that keeps switchgear and transformers within safe operating limits.

For NERC CIP registered entities, a relay of this class is frequently a medium or high impact BES Cyber Asset. A defect that permits privilege escalation directly implicates CIP-005 electronic access controls and CIP-007 account and access management. Under IEC 62443, this is a failure of the SR 1.x identification and authentication and SR 2.1 authorization enforcement requirements at the device level, and it undermines any zone and conduit model that assumed the relay enforced its own least-privilege roles.

Compensating Controls

Treat the web management interface as untrusted until the device is running a fixed firmware version. Do not rely on active vulnerability scanning to confirm exposure, since aggressive probing of protection relays can lock accounts, exhaust sessions, or in some cases disrupt device processing. Enumerate affected assets from passive traffic capture and configuration inventory instead.

Confirm the fixed firmware level directly with the vendor advisory before planning any relay firmware upgrade, and schedule it within a controlled maintenance outage rather than online.

BreachSpider Intel

BreachSpider tracks CVE-2026-62650 and related protection relay authorization defects across our OT vulnerability intelligence so operators can monitor exposure and validate compensating controls in real time.