Executive Summary
CVE-2026-62652 describes Siemens Reyrolle 7SR5 firmware in all versions below V2.70 shipping binaries that retain debugging symbols, which an unauthenticated attacker can pull from publicly available firmware update files to accelerate reverse engineering. The physical criticality is indirect but real: the 7SR5 is a protection relay that trips breakers on fault conditions, and anything that shortens the path to a memory-corruption or logic bug in that class of device threatens the primary layer of substation protection.
Technical Exposure Breakdown
The vulnerable component is the device firmware itself. During the build and release process, the binaries were not stripped of debugging symbols. Symbol tables map function names, variable names, and often source structure directly into the compiled artifact. For an analyst working with a stripped binary, function boundaries and semantics must be inferred through static and dynamic analysis, which is slow and error prone. When symbols are present, the reverse engineer gets a labeled map of the codebase for free.
The attack vector here is not the relay on the wire. It is the firmware distribution channel. Siemens publishes update files publicly, so an attacker never needs to touch an OT network, never needs credentials, and never triggers a single alert on a protection relay to obtain the artifact. The precondition is simply download access. This is why the CVSS score sits at 5.3. The flaw does not, by itself, grant code execution or data exfiltration. It is an enabler. It compresses the timeline between a researcher, or an adversary, deciding to study the 7SR5 and finding a memory-safety flaw, an authentication bypass, or a protocol-parsing defect that does carry direct impact.
Treat this as a supply-chain-adjacent information disclosure. The correct mental model is not "one bug" but "reduced cost of every future bug in this firmware line." Nation-state and well-resourced criminal actors already reverse relay firmware. This lowers the effort for the middle tier of adversary who previously lacked the patience or tooling.
OT Impact and Compliance Risk
A protection relay is not a general-purpose server. When it fails or is manipulated, breakers either trip when they should not, causing unplanned outages, or fail to trip when they should, allowing fault current to damage transformers, feeders, and connected loads. Neither failure mode is recoverable through a software rollback in the moment. The 7SR5 sits in distribution and industrial power protection, so the downstream physical consequence set spans nuisance tripping through equipment destruction.
For NERC CIP registered entities, unstripped firmware does not itself constitute a CIP-010 baseline deviation, but it feeds CIP-013 supply chain risk management obligations. Vendor practices that increase the reverse-engineering surface of firmware belong in your procurement risk assessments and vendor scorecards. Under IEC 62443, this maps to secure development lifecycle expectations in 62443-4-1, specifically the hardening and release-management practices that should strip non-production artifacts before shipping. Asset owners cannot remediate a vendor build defect, but they can and should hold it against the product security posture during selection and renewal.
Compensating Controls
There is no configuration change on the relay that removes symbols from firmware already published. Focus compensating effort on the follow-on risk this vulnerability enables.
- Treat the 7SR5 firmware line as higher exploitation risk. Prioritize monitoring for the class of vulnerabilities that reverse engineering tends to surface next: authentication, protocol parsing, and firmware validation.
- Enforce firmware signature and integrity validation on any update path. The information disclosure does not weaken signing, but adversaries who understand the firmware better will probe update handling first.
- Segment relay management interfaces. Keep engineering access to the 7SR5 on a dedicated management VLAN with explicit allow-lists. Do not rely on active scanning to enumerate these devices, since aggressive polling can disrupt protection relay processing and force unintended states.
- Virtual patching at the network layer. Build detection around anomalous engineering-session establishment and firmware-transfer patterns to the relay. A Suricata rule concept: alert on protocol sessions originating from any host outside the sanctioned engineering-workstation set toward relay management ports, tuned to your specific access baseline.
- Track the vendor advisory for a stripped firmware release and stage validation on a bench relay before deploying to protection-critical positions.
BreachSpider Intel
BreachSpider monitors the Reyrolle 7SR5 firmware line and correlated follow-on disclosures so protection engineers see the next exploitable defect before it reaches their substations.