CVE-2026-9650 Details
Description
CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenticated attacker accesses credentials stored within firmware or system files. With this credential an attacker could subsequently compromise the device if they have physical access to the device.
A vulnerability allowing unauthorized access and exposure of sensitive information has been identified in Schneider Electric's EasyLogic T150 (formerly Saitel DR) and Saitel DP Remote Terminal Unit & Controller products. This vulnerability arises from insufficient protection of credentials stored within firmware or system files. An unauthenticated attacker could access these credentials, which, if physical access to the device is gained, could lead to a compromise of the device.
Users can upgrade to version 11.06.32 of EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller or version 11.06.38 of Saitel DP Remote Terminal Unit & Controller, both of which include fixes for this vulnerability. These firmware versions are available through Schneider Electric's Customer Care Center. A reboot is required after applying the update.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-160-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-160-02.pdf | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-522 | Insufficiently Protected Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| schneider-electric easylogic t150 firmware | < 11.06.32 |
CPE
Remediation
| |
| schneider-electric easylogic t150 | All versions |
CPE
Remediation
| |
| schneider-electric saitel dp firmware | < 11.06.38 |
CPE
Remediation
| |
| schneider-electric saitel dp | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | Initial Analysis | [email protected] |
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2026 | New CVE Received | [email protected] |