External risk intelligence

Reyrolle 7SR5 Authentication Bypass via Session ID Exposure.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-62645

The product is an industrial protective relay. While it includes a web interface, these devices are typically deployed within isolated industrial control networks or behind protective firewalls. Public internet exposure is not a standard or intended deployment pattern for this class of hardware, despite the existence of a network-accessible interface.

Missing Authentication

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability exists in Reyrolle 7SR5 web interfaces, allowing unauthorized access by exposing session ID calculation. The main concern is confirming relevance and exposure due to the specialized nature of the affected technology.

  • Attackers can bypass logins.
  • Critical system access is at risk.
  • Confirm if this technology is in use.

Attack Path

How an attacker could exploit the issue

An attacker could begin by accessing the device's web interface. If the attacker can gather information about current and past session IDs, they might be able to bypass the device's authentication and gain unauthorized access.

  • No authentication required to access.
  • Web interface exposes session IDs.
  • Unauthorized access to the device.

Live Threat

Current exploitation, exposure, and threat context

The Reyrolle 7SR5 web interface may expose information that could enable an attacker to calculate session IDs. This could potentially allow an unauthenticated attacker to bypass authentication and gain unauthorized access to the device's functionalities.

  • Device authentication.
  • Unauthenticated session ID calculation.
  • Unauthorized access to device.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Reyrolle 7SR5 is a specialized industrial control device, meaning its ownership likely falls to industrial control system (ICS) or operational technology (OT) teams, with support from network and security teams for access and segmentation. The first practical step is to confirm if any of these devices are deployed, identify their network exposure, and determine if they are business-critical before planning any remediation.

  • ICS/OT teams should own the issue.
  • Verify device network exposure.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Reyrolle 7SR5?

The Reyrolle 7SR5 is an industrial protective relay used in power systems to monitor and guard electrical equipment. These devices play a critical role in managing energy distribution and infrastructure stability. They include a web interface that allows engineers to manage settings, monitor operations, and oversee device status over a local network.

How does CVE-2026-62645 create a security risk?

This vulnerability involves the exposure of sensitive session data, categorized as CWE-306: Missing Authentication for Critical Function. Specifically, the web interface reveals details that enable an attacker to mathematically derive active or previous session IDs. This flaw allows a remote user to bypass the standard login process and impersonate a legitimate administrator, potentially gaining full control over the device's functions.

Do I need to interact with the device to trigger this?

No, you do not need physical access or prior authentication. An attacker can exploit this remotely by interacting with the web interface to collect the necessary information for session ID calculation. Note that simply viewing the login page without attempting to gather session-specific data does not inherently trigger the vulnerability; it requires the successful extraction of the exposed session identifiers.

Is my device at risk if it is not on the internet?

Halo Surface Signal indicates that while the Reyrolle 7SR5 has a web interface, these devices are typically intended for isolated industrial control networks rather than public exposure. The risk is significantly higher if the device is reachable via the public internet. If your installation follows standard practices and keeps this hardware behind protective firewalls or within air-gapped segments, the likelihood of remote exploitation is substantially reduced.

What should I do if I manage Reyrolle 7SR5 units?

First, collaborate with your ICS or operational technology teams to locate all deployed units and verify their specific version numbers. Since this affects all versions below V2.70, confirm which devices are currently running outdated firmware. Prioritize checking your network perimeter to ensure these relays are not inadvertently accessible from untrusted networks while you coordinate with the vendor to plan your update process.

References