CVE-2026-8067 RTU500 Web 应用权限不当漏洞
影响已认证用户可触发设备重启,导致设备暂时不可用
AI 研判
CVE-2026-8067 是 RTU500 已停止支持(end-of-life)版本 Web 应用中的授权不当漏洞。已认证用户可通过 reset 端点触发设备重启,造成设备暂时不可用并中断其预期运行。
影响范围
RTU500
受影响的是 RTU500 已停止支持(end-of-life)版本的 Web 应用;具体版本号暂无公开信息。
漏洞详情
漏洞类型为授权不当(Improper Authorization)。Web 应用的 reset 端点未对已认证用户做充分的权限校验,导致普通已认证用户也能调用该端点触发设备重启。利用方式为登录后向 reset 端点发送请求。
利用条件与风险
利用前提是攻击者需先获得一个有效的已认证账户。成功利用可造成设备暂时不可用和运行中断,属于拒绝服务类风险,CVSS 6.5 为中危。
修复建议
官方修复方案暂无公开信息;由于受影响版本已停止支持,建议升级或迁移至仍在维护的版本,并限制 Web 应用访问权限、及时清理不必要的账户作为临时缓解。
原始情报
An improper authorization vulnerability in the end-of-life versions of RTU500’s web application allows an authenticated user to trigger the RTU500 to reboot through the reset endpoint. Successful exploitation could cause temporary device unavailability and disruption of its intended operation.