RTU500 Firmware Advisory Spans Multiple Branches

The operational risk here is version precision. RTU500 CMU firmware is split across several affected branches, so operators cannot assume one fleet-wide baseline or one fix covers every unit; a bad PKCS#12 certificate can crash the firmware and take communications or control-plane visibility with it. CISA reposted the Hitachi Energy advisory for RTU500 CMU firmware versions 12.7.1–12.7.7, 13.5.1–13.5.4, 13.6.1–13.6.3, 13.7.1–13.7.8, and 13.8.1. Hitachi lists seven CVEs, including CVE-2025-69421, and says the impact is primarily availability. The issue is triggered when a privileged user uploads a malformed PKCS#12 certificate or when PKI client functionality is enabled. The fix is not one universal upgrade. Hitachi maps remediation to specific firmware branches, including CMU Firmware 13.7.9 and 13.8.2, so exact inventory is the deciding factor for exposure.

Part of the PlainSec briefing for 2026-06-05

Sources