Status: UPDATED | Advisory ID: CVE-2026-9650
| CVE | CVE-2026-9650 |
| CVSS Score / Version | 7.5 (High) / CVSS v3.1 |
| Updated | 2026-07-14 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is none. |
| Affected products | Schneider Electric EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller, Schneider Electric Saitel DP Remote Terminal Unit & Controller, Schneider Electric easylogic_t150_firmware, and Schneider Electric saitel_dp_firmware |
| Classified as | CWE-522 (Insufficiently Protected Credentials) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Schneider Electric | EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller | ||
| Schneider Electric | Saitel DP Remote Terminal Unit & Controller | ||
| Schneider Electric | easylogic_t150_firmware | ||
| Schneider Electric | saitel_dp_firmware |
| Subsystems | General OT |
| Sectors | Multiple |
CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenticated attacker accesses credentials stored within firmware or system files. With this credential an attacker could subsequently compromise the device if they have physical access to the device. (NVD)
Monitor Schneider Electric's web page for any future patch releases. See vendor advisory link below.