Schneider Electric RTU credential flaws patched
Schneider Electric fixed two credential-handling vulnerabilities in EasyLogic T150 and Saitel DP RTUs that could expose sensitive information to unauthenticated or privileged attackers.
CISA published an ICS advisory detailing two vulnerabilities in Schneider Electric's EasyLogic T150 and Saitel DP remote terminal units (RTUs) used in critical manufacturing and energy sectors worldwide. CVE-2026-9650 is an insufficiently protected credentials weakness that allows unauthenticated attackers to access credentials stored in firmware or system files, potentially leading to device compromise if physical access is obtained. CVE-2026-9651 involves incorrect permission assignment, enabling attackers with privileged local access to read improperly protected system files and extract password hashes.
The vulnerabilities affect EasyLogic T150 firmware versions up to 11.06.30 (CVE-2026-9650) and 11.06.31 (CVE-2026-9651), and Saitel DP firmware versions up to 11.06.35 and 11.06.37 respectively. Schneider Electric has released patched firmware versions 11.06.32 for EasyLogic T150 and 11.06.38 for Saitel DP, available through their Customer Care Center. The fixes require a device reboot after installation.
No active exploitation has been reported to CISA. The vulnerabilities were disclosed through coordinated disclosure, with CVE-2026-9650 reported by Dick Brooks of Business Cyber Guardian and CVE-2026-9651 identified by an internal Schneider Electric researcher. CISA recommends standard ICS defensive measures including network segmentation, firewall isolation, and secure remote access methods.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-04
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free