← All Advisories

CVE-2026-9650

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-9650

Key Details

CVECVE-2026-9650
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-07-14
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is none.
Affected productsSchneider Electric EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller, Schneider Electric Saitel DP Remote Terminal Unit & Controller, Schneider Electric easylogic_t150_firmware, and Schneider Electric saitel_dp_firmware
Classified asCWE-522 (Insufficiently Protected Credentials)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Schneider ElectricEasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller
Schneider ElectricSaitel DP Remote Terminal Unit & Controller
Schneider Electriceasylogic_t150_firmware
Schneider Electricsaitel_dp_firmware
SubsystemsGeneral OT
SectorsMultiple

What to Know

CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenticated attacker accesses credentials stored within firmware or system files. With this credential an attacker could subsequently compromise the device if they have physical access to the device. (NVD)

What to Do

Monitor Schneider Electric's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-9650
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-9650
Vendor advisoryhttps://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-160-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-160-02.pdf