CVE-2019-18253: Hitachienergy Relion 670 Firmware
Critical severity, CVSS 10.0. EPSS: 2% chance of exploitation in the next 30 days.
An attacker could use specially crafted paths in a specific request to read or delete files from Relion 670 Series (versions 1p1r26, 1.2.3.17, 2.0.0.10, RES670 2.0.0.4, 2.1.0.1, and prior) outside the intended directory.
Affected products
- Hitachienergy Relion 670 Firmware: before 1p1r26 (fixed in 1p1r26); from 1.2, before 1.2.3.17 (fixed in 1.2.3.17); from 2.0, before 2.0.0.10 (fixed in 2.0.0.10); from 2.1, before 2.1.0.1 (fixed in 2.1.0.1)
Published 2019-11-27. Last modified 2026-06-17.