SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-62654

MEDIUM · CVSS 6.8 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability exists in Reyrolle 7SR5 devices running versions prior to V2.70, where an attacker with physical access can activate a maintenance mode that allows the device to download and execute unsigned code from a network server without verification. This could lead to unauthorized code execution, potentially compromising the device's integrity and functionality. Organizations using these devices should prioritize remediation to mitigate risks associated with physical security breaches.

CVE
CVE-2026-62654
Severity
MEDIUM
CVSS
6.8
EPSS
0.11%

Original NVD Description

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A special maintenance mode can be activated via a physical key sequence during device boot, in which the device downloads and executes program code from a network server without verifying its authenticity or integrity. This could allow an attacker with physical access to the device to upload and execute arbitrary, unsigned code.