Executive Summary
CVE-2026-62653 is a memory corruption condition in the Reyrolle 7SR5 protection relay (all versions below V2.70) triggered by unvalidated input over a proprietary communication protocol that becomes reachable only when the device is placed into a special firmware-update mode. An unauthenticated attacker with physical access can crash the relay and potentially execute arbitrary code, which for a protective relay means the loss or corruption of the device that trips breakers to isolate faults on the electrical grid.
Technical Exposure Breakdown
The vulnerable component is the parser handling a proprietary protocol on the 7SR5. Under normal operation this attack surface is not present. It is exposed specifically when the device is transitioned into firmware-update mode. In that state the relay accepts input over the proprietary channel, and that input is not properly validated before it is written into memory, producing the corruption condition.
The attack vector is physical. The grounding data describes an unauthenticated attacker with physical access, and the assigned CVSS score of 6.8 is consistent with a local access requirement combined with a high potential impact. This is not a remotely reachable flaw across a routed network. It requires an actor at the relay, at the cabinet, or with a maintenance connection during an update window.
The important structural detail is the pairing of two conditions: the device must be in firmware-update mode, and the attacker must have a path to the proprietary protocol at that moment. Firmware-update mode is a transient state, but it is also a state that is frequently entered during commissioning, patch cycles, and field service. That is precisely when physical access controls are relaxed and multiple people are working around the panel.
OT Impact and Compliance Risk
A protection relay is not a general purpose computer. It is the component that decides whether a fault becomes an isolated event or a cascading one. A crash of the 7SR5 removes protection coverage for the zone it defends. Arbitrary code execution on the relay is worse, because it opens the door to manipulating trip logic, settings, or the reporting the operator relies on to trust the device. A compromised relay can misoperate, fail to operate, or lie about its state.
For NERC CIP registered entities, a relay that can be placed into a code execution condition through physical access reinforces the CIP-006 physical security perimeter obligations and the CIP-010 configuration and firmware change management controls around update windows. Under IEC 62443, this is a failure of input validation at the component level that maps to the relevant foundational requirements for use control and system integrity. Utilities operating under water sector obligations such as AWIA 2018 that use similar protection and control assets should treat firmware-update states as elevated risk periods in their risk and resilience assessments.
Compensating Controls
Do not treat vendor patching as the only response, and note that patch status for this CVE is not confirmed in available data. The primary compensating control here is procedural and physical, because the attack surface is only live during firmware-update mode.
- Restrict entry into firmware-update mode to controlled, logged maintenance windows with two-person integrity and documented start and end times.
- Enforce physical access controls at the relay cabinet during any update. The vulnerability requires physical proximity, so a hardened perimeter directly reduces exploitability.
- Isolate the maintenance connection used during updates. Do not leave engineering laptops or update tooling connected to broader networks while a relay is in update mode.
- Passively baseline the proprietary protocol traffic. A Suricata concept here would alert on unexpected sessions on the update channel outside of scheduled windows, since any traffic to that protocol when no update is authorized is itself an anomaly.
Active scanning of protection relays is not a valid discovery method for this class of device. Probing a 7SR5 in the field can disturb or brick a component whose job is to protect the grid. Inventory and version identification should come from passive collection and from configuration records, not from a live scan against the relay.
BreachSpider Intel
BreachSpider tracks CVE-2026-62653 and related protection relay exposures against live advisory revisions and exploitation signals, and can monitor your OT asset base for affected versions without touching the devices themselves.