Vulnerabilities & Exploits · IoT / OT Attack
The operational risk here is version precision. RTU500 CMU firmware is split across several affected branches, so operators cannot assume one fleet-wide baseline or one fix covers every unit; a bad PKCS#12 certificate can crash the firmware and take communications or control-plane visibility with it.
CISA reposted the Hitachi Energy advisory for RTU500 CMU firmware versions 12.7.1–12.7.7, 13.5.1–13.5.4, 13.6.1–13.6.3, 13.7.1–13.7.8, and 13.8.1. Hitachi lists seven CVEs, including CVE-2025-69421, and says the impact is primarily availability. The issue is triggered when a privileged user uploads a malformed PKCS#12 certificate or when PKI client functionality is enabled.
The fix is not one universal upgrade. Hitachi maps remediation to specific firmware branches, including CMU Firmware 13.7.9 and 13.8.2, so exact inventory is the deciding factor for exposure.
1 source · Jun 4
CVEs in this update
7 CVEs
Across Secure Enterprise VPN Server, OpenShift, Splunk Enterprise, and related packages.
0 critical · 1 high · 3 medium · 2 low
0 in CISA KEV · 0 with EPSS above 1%
Highest severity: CVE-2025-69421 · 7.5 HIGH
Highest EPSS: CVE-2025-69421 · 0.88%
CISA Advisories
Hitachi Energy RTU500 | CISA
Hitachi Energy RTU500 Summary Hitachi Energy is aware of vulnerabilities that affect RTU500 product versions listed in this document.
originalPart of the PlainSec briefing for 2026-06-04
Every edition of this story: RTU500 Firmware Advisory Spans Multiple Branches