Schneider Electric EasyLogic T150 and Saitel DP RTU Insufficiently Protected Credentials and Permission Assignment Vulnerabilities
First seen Jul 4, 2026 · Updated Jul 4, 2026 · CVSS 7.5
Schneider Electric EasyLogic T150 and Saitel DP RTU devices contain two vulnerabilities that could allow unauthorized access to sensitive credentials and password hashes. CVE-2026-9650 allows an unauthenticated attacker with physical access to extract credentials from firmware or system files, while CVE-2026-9651 allows a privileged local attacker to read improperly protected system files containing password hashes. No public exploitation has been reported to CISA at this time.
Technical Analysis
CVE-2026-9650 (CWE-522: Insufficiently Protected Credentials, CVSS v3.1 7.5/HIGH, CVSS v4.0 8.7) enables an unauthenticated attacker with physical device access to retrieve credentials stored insecurely within firmware or system files, potentially leading to full device compromise. CVE-2026-9651 (CWE-732: Incorrect Permission Assignment for Critical Resource, CVSS v3.1 4.4/MEDIUM, CVSS v4.0 6.7) allows a locally privileged attacker to read improperly permissioned system files, exposing password hashes for potential offline cracking and account compromise. Both vulnerabilities affect firmware present in EasyLogic T150 (formerly Saitel DR) and Saitel DP RTU/Controller product lines, with attack vectors requiring either physical or local privileged access rather than remote network exploitation. Exploitation could serve as an initial foothold for further compromise of RTU-based control systems in critical infrastructure environments.
Affected Systems
Schneider Electric EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller firmware <=11.06.30 (CVE-2026-9650) and <=11.06.31 (CVE-2026-9651); Schneider Electric Saitel DP Remote Terminal Unit & Controller firmware <=11.06.35 (CVE-2026-9650) and <=11.06.37 (CVE-2026-9651). Fixed in firmware versions 11.06.32 (EasyLogic T150) and 11.06.38 (Saitel DP).
Indicators of Compromise
- No known IOCs; no public exploitation reported to CISA at this time.
Remediation Steps
- 1
Apply vendor firmware updates
Update EasyLogic T150 (formerly Saitel DR) RTU & Controller to firmware version 11.06.32 and Saitel DP RTU & Controller to firmware version 11.06.38 by contacting Schneider Electric's Customer Care Center. A device reboot is required after updating.
- 2
Restrict physical access
Limit physical access to RTU/controller devices to trusted personnel only, as CVE-2026-9650 requires physical access for exploitation.
- 3
Enforce least privilege
Restrict local privileged account access on affected devices to reduce risk of CVE-2026-9651 exploitation via improperly protected system files.
- 4
Network segmentation
Isolate control system networks and RTU devices behind firewalls, separate from business networks, and ensure no direct internet exposure.
- 5
Secure remote access
Where remote access is necessary, require VPN connections with up-to-date VPN software and strong authentication.
- 6
Review Schneider Electric advisory
Consult Schneider Electric CPCERT security advisory SEVD-2026-160-02 for detailed mitigation and workaround guidance.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.