MAJOR

Hitachi Energy Advises Security Updates Amid Product Vulnerabilities

Hitachi Energy announces critical updates following identified vulnerabilities in multiple products.

By TradepilotUSA News Desk

Published · 1 min read

Media: © OpenStreetMap contributors · OpenFreeMap · USGS

Hitachi Energy has issued critical security updates for several of its products following the discovery of multiple vulnerabilities. The company, headquartered in Switzerland, has identified issues affecting its REB500, SOI, and RTU500 products, which are deployed worldwide in critical infrastructure sectors such as energy.

REB500 Vulnerabilities

The REB500 product is affected by open-source software vulnerabilities that could be exploited to execute Denial of Service (DoS) attacks. According to the Cybersecurity and Infrastructure Security Agency (CISA), the affected versions include REB500/<=8. 3.

3. 1, associated with CVE-2024-8176 and CVE-2025-59375. These vulnerabilities involve a stack overflow in the libexpat library used by the IEC61850 functionality, which could lead to DoS or memory corruption if exploited by an authenticated malicious user with local access.

Hitachi Energy recommends updating to version 8. 3. 4.

0 to mitigate these risks.

SOI Product Vulnerability

Hitachi Energy has also identified a Remote Code Execution (RCE) vulnerability in the Apache ActiveMQ component of its SOI product, affecting versions between 2. 0. 0 and 2.

2. 0. This vulnerability, identified as CVE-2026-34197, has a high base score of 8.

8 according to CVSS version 3. 1. It involves improper input validation and code injection, allowing an authenticated attacker to execute arbitrary code.

To address this, users are advised to apply the SOI EP2 patch, which upgrades the ActiveMQ version to 5. 19. 5 and includes other security enhancements.

RTU500 Firmware Issues

The RTU500 series is also under scrutiny due to vulnerabilities reported by Dragos. These affect end-of-life firmware versions 11. x and prior, which lack modern security controls.

Vulnerabilities such as CVE-2026-8065, CVE-2026-8066, and CVE-2026-8067 allow unauthorized actions like uploading arbitrary firmware, overwriting files, and triggering reboots. Hitachi Energy advises upgrading to firmware versions 12. 7.

8 or 13. 9. 1 to enhance security.

Recommendations and Mitigation

CISA and Hitachi Energy recommend several defensive measures to minimize exploitation risks. These include applying the latest patches, using firewalls to isolate control system networks, and following cybersecurity best practices. Users are encouraged to contact Hitachi Energy for further support and guidance on securing their systems.

Sources (1)

TradepilotUSA News writes each story in its own words from the independent reports listed above and links to them. How we report · Report a correction

More stories

More Tech

Related clips

All clips