Executive Summary

CVE-2026-62645 exposes information through the Reyrolle 7SR5 web interface that lets an attacker calculate current and past session ID numbers, defeating authentication and granting unauthorized device access. Because the 7SR5 is a protective relay, a compromised session gives an attacker direct reach into the logic that trips breakers and protects primary plant, making this a physical protection integrity problem rather than a data confidentiality nuisance.

Technical Exposure Breakdown

The grounding data identifies the affected product as Reyrolle 7SR5 in all versions below V2.70, with a CVSS score of 9.8. The flaw is not a memory corruption or a supply chain issue. It is a session management weakness. The web interface leaks enough information for an attacker to reconstruct the algorithm or seed used to generate session IDs, which means valid and previously valid session tokens become predictable rather than random.

Once session IDs are predictable, the authentication step is effectively decorative. An attacker who can reach the web interface does not need credentials. They compute a valid session ID, present it, and the device treats them as an authenticated operator. The CVSS 9.8 rating is consistent with a network-reachable, low-complexity, no-authentication attack that yields full compromise of confidentiality, integrity, and availability.

The practical precondition is network reachability to the relay web service. In a properly segmented substation this interface should never be exposed beyond an engineering VLAN. In practice we routinely observe protection relay management interfaces bridged onto shared operations networks, reachable from jump hosts, and in the worst cases exposed to routable corporate space. Every one of those paths converts a theoretical weakness into a direct attack.

OT Impact and Compliance Risk

A protective relay that accepts a forged session is a relay whose settings, protection thresholds, and trip logic can be altered by an unauthenticated party. That translates to real physical outcomes: suppressed trips that allow faults to damage transformers and switchgear, or spurious trips that drop load and destabilize a bus. This is exactly the class of manipulation that turns a network intrusion into a hardware and safety event.

For NERC CIP registered entities, a relay with a network-accessible interface subject to authentication bypass is a Medium or High impact BES Cyber Asset with a broken CIP-005 electronic security perimeter assumption and a CIP-007 access control failure. Under IEC 62443, this defeats the FR 1 identification and authentication control and undermines any SL-2 or higher claim for the zone containing these relays. Utilities operating water and wastewater assets under AWIA 2018 that use these relays in pumping or treatment power distribution should treat this as a control system authentication failure requiring documented risk reassessment.

Compensating Controls

Patch status is unknown in the available data, so build a plan that does not depend on a fix being available or installable during your maintenance window. Note also that active scanning of protection relays can destabilize or brick these devices, so do not run aggressive vulnerability scanners against energized 7SR5 units to inventory them. Use passive discovery and configuration records instead.

Validate the fixed version and its interface behavior in a lab against non-production hardware before staging any firmware change to energized relays.

BreachSpider Intel Footer

BreachSpider tracks protection relay and ICS authentication exposures like CVE-2026-62645 across 25,000+ ICS CVEs and 175,000+ OT products so operators can monitor reachability and patch status without touching live equipment.