SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-62648

HIGH · CVSS 7.5 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability exists in Reyrolle 7SR5 devices running versions prior to V2.70, where improper validation of URL lengths in pre-authenticated HTTP messages can lead to an out-of-bounds write condition. This flaw enables unauthenticated remote attackers to crash the device, causing a denial-of-service by triggering a reboot. Organizations using affected Reyrolle devices should prioritize patching to mitigate the risk of service disruption.

CVE
CVE-2026-62648
Severity
HIGH
CVSS
7.5
EPSS
0.33%

Original NVD Description

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The length of the URL component contained in pre-authenticated HTTP messages is not properly validated before appending additional data to it, resulting in an out-of-bounds write condition in memory. This could allow an unauthenticated remote attacker to crash the affected device, causing a reboot and resulting in a denial-of-service condition.