SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2026-1772

RTU500 web interface: An unprivileged user can read user management information.

MEDIUM 5.3EPSS 0.26%

Does this matter?

Lower severity and a low EPSS score (0.26%). Track it; it rarely justifies an emergency change on its own.

Description

RTU500 web interface: An unprivileged user can read user management information. The information cannot be accessed via the RTU500 web user interface but requires further tools like browser development utilities to access them without required privileges.

CVSS 4.0
5.3 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
0.26% probability · 18th percentile
CISA KEV
Not listed
Weakness
CWE-280
Affected
hitachienergy/rtu520 firmware · hitachienergy/rtu530 firmware · hitachienergy/rtu540 firmware · hitachienergy/rtu560 firmware
Source
cybersecurity@hitachienergy.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.