CVE-2026-1773: Hitachienergy RTU520 Firmware
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
IEC 60870-5-104 used in RTU500: Potential Denial of Service impact on reception of invalid U-format frame. Product is only affected if IEC 60870-5-104 bi-directional functionality is configured. Enabling secure communication following IEC 62351-3 does not remediate the vulnerability but mitigates the risk of exploitation.
Affected products
- Hitachienergy RTU520 Firmware: from 12.7.1, up to and including 12.7.7; from 13.5.1, up to and including 13.5.4; from 13.6.1, up to and including 13.6.2; from 13.7.1, before 13.7.8 (fixed in 13.7.8); version 13.8.1 only
- Hitachienergy RTU530 Firmware: from 12.7.1, up to and including 12.7.7; from 13.5.1, up to and including 13.5.4; from 13.6.1, up to and including 13.6.2; from 13.7.1, before 13.7.8 (fixed in 13.7.8); version 13.8.1 only
- Hitachienergy RTU540 Firmware: from 12.7.1, up to and including 12.7.7; from 13.5.1, up to and including 13.5.4; from 13.6.1, up to and including 13.6.2; from 13.7.1, before 13.7.8 (fixed in 13.7.8); version 13.8.1 only
- Hitachienergy RTU560 Firmware: from 12.7.1, up to and including 12.7.7; from 13.5.1, up to and including 13.5.4; from 13.6.1, up to and including 13.6.2; from 13.7.1, before 13.7.8 (fixed in 13.7.8); version 13.8.1 only
Published 2026-02-24. Last modified 2026-06-17.