Download of code without integrity check in Reyrolle 7SR5 - CVE-2026-62654

 

Download of code without integrity check in Reyrolle 7SR5 - CVE-2026-62654

Published: September 9, 2026


Vulnerability identifier: #VU148480
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-62654
CWE-ID: CWE-494
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to compromise the affected system

The vulnerability exists due to software does not perform software integrity check when downloading updates. An attacker with physical access can upload and execute arbitrary code on the system.


Affected software

Reyrolle 7SR5

How to mitigate CVE-2026-62654

Install updates from vendor's website.

Reyrolle 7SR5 - update to 2.70

External References

Related Security Bulletins