External risk intelligence

Reyrolle 7SR5 Predictable Random Number Generator Vulnerability Allows Impersonation.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-62647

The product is a Reyrolle 7SR5 protection relay, which is specialized industrial control equipment. While network-reachable in some deployments for monitoring or configuration, these devices are typically managed within restricted operational technology (OT) networks behind firewalls or gateways, making direct public internet exposure uncommon.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in a Reyrolle device that could allow an unauthenticated attacker to predict security-related values, potentially enabling them to impersonate legitimate users and gain unauthorized access.

  • Predictable security values allow unauthorized access.
  • Matters if the affected device is externally accessible.
  • Confirm relevance and exposure for this specific asset.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can remotely exploit this vulnerability by targeting the predictable random number generator used for security-sensitive values like session identifiers. By guessing these values, an attacker could impersonate a legitimate user to gain unauthorized access to the device.

  • No authentication or network access needed.
  • Predictable random numbers for session identifiers.
  • Unauthorized access to the device.

Live Threat

Current exploitation, exposure, and threat context

The predictability of random number generation in Reyrolle 7SR5 devices could allow an unauthenticated remote attacker to impersonate a legitimate user, potentially gaining unauthorized access to the device. This is possible when the device is accessible remotely and its security-relevant values are not sufficiently protected.

  • Protected device access.
  • Predicting random number sequences.
  • Unauthorized system access.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts industrial control systems, likely managed by infrastructure or operations technology (OT) teams. The first practical step is to identify all instances of the Reyrolle 7SR5, determine their network exposure, confirm business criticality, and then assign ownership for remediation planning.

  • Own: Infrastructure and OT teams.
  • Verify: Device network reachability and criticality.
  • Action: Plan vendor-coordinated updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Reyrolle 7SR5?

The Reyrolle 7SR5 is a specialized protection relay used in industrial control systems to monitor and safeguard electrical power grids and equipment. These devices are critical infrastructure components designed to manage power distribution and detect electrical faults, ensuring the stability and safety of utility and industrial networks.

What does CWE-20 mean for CVE-2026-62647?

CWE-20 refers to improper input validation, which occurs when a system fails to verify data effectively. In this case, the device uses a predictable method for creating security values, like session IDs, instead of a truly random one. Because the system does not validate the randomness of these inputs, an attacker can anticipate upcoming identifiers to bypass security checks.

How can someone trigger this vulnerability?

An attacker triggers this by remotely monitoring the sequence of security-related values generated by the device. Because the random number generator is not cryptographically sound, it creates predictable patterns. The vulnerability is not triggered by localized, physical interaction with the device buttons; it requires remote network communication to observe and guess the session identifiers.

Do I need to worry if my Reyrolle 7SR5 is not on the internet?

According to Halo Surface Signal, these relays are typically found in restricted operational technology networks behind firewalls, making direct public internet exposure uncommon. If your device is segmented from the internet, the risk is lower; however, you should still care if unauthorized parties could reach the device over your internal network.

What is the first step to address this CVE?

Begin by creating an inventory of all your Reyrolle 7SR5 units to verify which versions are currently in use. Coordinate with your OT and infrastructure teams to check if the identified devices are reachable over the network. Once you have confirmed their locations and reachability, work toward planning a vendor-coordinated firmware update to resolve the underlying random number generation issue.

References