Reyrolle 7SR5 Auth Bypass via Web Interface (pre-V2.70)
CVE-2026-62645 Published on September 8, 2026

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed through the web interface that can be used to calculate the current and past session ID numbers. This could allow an attacker to bypass the authentication and gain unauthorized access to the device.

NVD

Weakness Type

Missing Authentication for Critical Function

The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.


Affected Versions

Siemens Reyrolle 7SR5: