# Siemens Reyrolle 7SR5 relays get patched for 14 flaws

Published: 2026-09-15 · Severity: routine · Sectors: energy
Canonical: https://vorant.io/reports/14981e24-ede5-52d7-b51f-582088f65ce9/siemens-reyrolle-7sr5-relays-get-patched-for-14-flaws

> Siemens fixed 14 vulnerabilities in Reyrolle 7SR5 protection relays before V2.70, including auth bypass, DoS, and code-execution issues; update to V2.70+.

Siemens has disclosed 14 vulnerabilities affecting Reyrolle 7SR5 protective relay devices running firmware prior to V2.70, used in energy sector critical infrastructure worldwide. Five of the flaws (CVE-2024-42384/42385/42386/42391/42392) stem from the embedded Cesanta Mongoose web server and allow remote attackers to crash the device via malformed TLS packets or trigger memory corruption/infinite loops via malformed PEM certificates or input strings.

The remaining nine CVEs (CVE-2026-62645 through 62654, excluding 62651) are Siemens-specific weaknesses in the device's web management interface and firmware. These include predictable/low-entropy session identifiers and insufficient RNG initialization that could let an unauthenticated remote attacker derive valid sessions and impersonate an authenticated user (CVE-2026-62645/62646/62647); an out-of-bounds write from unvalidated URL length in pre-auth HTTP messages causing remote DoS/reboot (CVE-2026-62648); resource exhaustion under high concurrent HTTP load causing device crash (CVE-2026-62649); and a server-side RBAC bypass allowing a low-privileged authenticated user to escalate to admin (CVE-2026-62650). Physical-access issues include unremoved debug symbols easing firmware reverse engineering (CVE-2026-62652), memory corruption in a proprietary firmware-update protocol enabling potential code execution (CVE-2026-62653), and a maintenance mode activated via a physical key sequence that downloads and executes unsigned code from a network server without integrity checks (CVE-2026-62654).

Siemens has released V2.70 to remediate all issues and recommends applying it via documented update procedures. No exploitation in the wild has been reported; this is a coordinated vendor disclosure via Siemens ProductCERT (SSA-142885) republished by CISA. Standard ICS hardening is advised: network segmentation, isolating control system networks from business/internet-facing networks, and secure remote access via VPN where required.

## Mentioned in this report

- Vulnerabilities: CVE-2024-42384, CVE-2024-42385, CVE-2024-42386, CVE-2024-42391, CVE-2024-42392, CVE-2026-62645, CVE-2026-62646, CVE-2026-62647, CVE-2026-62648, CVE-2026-62649, CVE-2026-62650, CVE-2026-62652, CVE-2026-62653, CVE-2026-62654

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-05

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/14981e24-ede5-52d7-b51f-582088f65ce9/siemens-reyrolle-7sr5-relays-get-patched-for-14-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
