Vulnerabilities & Exploits
CISA says Siemens Reyrolle 7SR5 protection relays before V2.70 are affected by 14 vulnerabilities, and Siemens has released V2.70 as the fix. The advisory covers units deployed worldwide in the energy sector.
Several of the flaws sit in the Cesanta Mongoose web server inside the relay. A malformed TLS packet or bad certificate text can fault the application, crash the web server, or force it into an endless loop, which can knock out the management interface operators use to see or control the relay.
For sites that depend on that web interface, the exposure is an OT availability problem first and a software bug second: the relay may still protect the circuit, but the loss of its web server can interrupt visibility and administration across fleet deployments until the affected units are updated.
1 source · 20h ago
CVEs in this update
14 CVEs
Across Mongoose Web Server, mongoose, Reyrolle 7SR5.
1 critical · 7 high · 6 medium · 0 low
0 in CISA KEV · 0 with EPSS above 1%
Highest severity: CVE-2026-62645 · 9.8 CRITICAL
Highest EPSS: CVE-2024-42384 · 0.48%
Showing the top 10 by KEV, EPSS, and severity.
CISA Advisories
Siemens Reyrolle 7SR5 | CISA
Siemens Reyrolle 7SR5 Summary Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities.
originalPart of the PlainSec briefing for 2026-09-16
Every edition of this story: Siemens Reyrolle Relay Bug Threatens OT Availability