External risk intelligence

Reyrolle 7SR5 Predictable Session Identifiers Allow Remote Authentication Bypass

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-62646

The product is the Reyrolle 7SR5, which is an industrial protection relay. While network-reachable, these devices are typically deployed in isolated operational technology (OT) environments or behind strict internal network controls rather than being directly exposed to the public internet.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in Reyrolle 7SR5 technology could allow unauthenticated remote attackers to bypass authentication by predicting or brute-forcing session identifiers. The main concern is confirming the relevance and exposure of this technology within your environment.

  • Predictable session IDs allow unauthorized access.
  • Protects industrial control systems from remote attacks.
  • Verify if Reyrolle 7SR5 is in use.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by targeting the Reyrolle 7SR5 remotely over a network. They would attempt to guess or derive a valid session identifier, bypassing the need for legitimate authentication. Successful bypass could allow the attacker to access the device.

  • No authentication required for access.
  • Predictable session identifiers are guessed.
  • Unauthorized access to the device.

Live Threat

Current exploitation, exposure, and threat context

A vulnerability in Reyrolle 7SR5 could allow an unauthenticated remote attacker to bypass authentication by predicting or brute-forcing session identifiers due to insufficient randomness in the generation algorithm. This could affect the service's ability to control access.

  • Authentication bypass.
  • Predictable session identifiers.
  • Unauthorized service access.

Operational Fix

Recommended remediation, mitigation, and detection steps

Addressing this vulnerability requires coordination between the asset owner responsible for the Reyrolle 7SR5 devices and the security team. The first step is to identify all instances of the affected technology, confirm their network exposure and criticality, and then engage the accountable owner to plan remediation.

  • Ownership: Asset owner responsible for Reyrolle 7SR5.
  • Verify: Network exposure and operational criticality.
  • Action: Plan and coordinate vendor engagement.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Reyrolle 7SR5?

The Reyrolle 7SR5 is an industrial protection relay used to monitor and manage electrical power systems. These specialized devices ensure the safety and reliability of grid infrastructure by detecting faults and triggering protective actions. Because they operate within critical power environments, maintaining secure access to their management interfaces is essential for ongoing operations.

How does CVE-2026-62646 impact session security?

This vulnerability relates to CWE-331, which involves insufficient entropy in random number generation. In this case, the Reyrolle 7SR5 uses an algorithm that produces predictable session identifiers. Because these tokens are not sufficiently random, an attacker can mathematically determine or guess valid session keys, effectively bypassing the device's authentication mechanisms to gain unauthorized control.

Does network interaction always trigger this bug?

While the vulnerability is reachable over a network, it does not trigger automatically through simple connectivity. An attacker must specifically target the authentication process by observing or repeatedly testing session generation to derive a valid token. Simply interacting with other device functions or background services does not inherently exploit the flaw; it requires a focused attempt to brute-force or predict the weak session identifiers.

How do I determine if my Reyrolle 7SR5 is at risk?

Halo Surface Signal suggests that while these devices are network-reachable, they are typically found in isolated operational technology (OT) environments rather than on the public internet. You should assess risk by verifying if your specific units are behind strict network controls or are unintentionally accessible from broader internal or external networks, which would change your exposure level.

What should I do to secure my devices?

The initial step is to conduct an internal audit to identify all Reyrolle 7SR5 installations in your environment. Once identified, evaluate their specific network connectivity and operational role. Coordinate with the asset owners to confirm whether these devices are currently running versions affected by this vulnerability and to establish a plan for applying vendor-provided updates.

References