Executive Summary
In June 2026, Schneider Electric disclosed two critical vulnerabilities affecting their EasyLogic T150 and Saitel DP Remote Terminal Units (RTUs). The first, CVE-2026-9650, involves insufficiently protected credentials, allowing unauthenticated attackers to access sensitive information stored within firmware or system files. The second, CVE-2026-9651, pertains to incorrect permission assignments for critical resources, enabling attackers with privileged local access to read improperly protected system files, potentially leading to account compromise. These vulnerabilities pose significant risks to critical infrastructure sectors, including manufacturing and energy, as they could lead to unauthorized access and control over essential systems.
The disclosure of these vulnerabilities underscores the ongoing challenges in securing industrial control systems (ICS). As cyber threats targeting ICS continue to evolve, organizations must remain vigilant, regularly updating and patching their systems to mitigate potential risks. This incident highlights the importance of proactive cybersecurity measures and the need for continuous monitoring to protect critical infrastructure from emerging threats.
Why This Matters Now
The vulnerabilities in Schneider Electric's RTUs highlight the persistent risks in industrial control systems, emphasizing the urgent need for organizations to implement robust cybersecurity measures to protect critical infrastructure from evolving cyber threats.
Attack Path Analysis
An unauthenticated attacker exploited insufficiently protected credentials in the firmware of Schneider Electric EasyLogic T150 and Saitel DP RTU devices, gaining unauthorized access. With these credentials, the attacker escalated privileges to gain administrative control over the devices. The attacker then moved laterally within the network to access other critical systems. They established a command and control channel to maintain persistent access. Sensitive data was exfiltrated from the compromised devices. Finally, the attacker disrupted operations by altering device configurations, leading to potential service outages.
Kill Chain Progression
Initial Compromise
Description
An unauthenticated attacker accessed credentials stored within firmware or system files of Schneider Electric EasyLogic T150 and Saitel DP RTU devices, exploiting insufficiently protected credentials.
Related CVEs
CVE-2026-9650
CVSS 8.7An insufficiently protected credentials vulnerability in Schneider Electric EasyLogic T150 and Saitel DP RTU allows unauthorized access and exposure of sensitive information when an unauthenticated attacker accesses credentials stored within firmware or system files.
Affected Products:
Schneider Electric EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller – <=11.06.30
Schneider Electric Saitel DP Remote Terminal Unit & Controller – <=11.06.35
Exploit Status:
no public exploitCVE-2026-9651
CVSS 6.7An incorrect permission assignment for critical resource vulnerability in Schneider Electric EasyLogic T150 and Saitel DP RTU allows unauthorized disclosure of password hashes and potential account compromise when an attacker with privileged local access reads improperly protected system files.
Affected Products:
Schneider Electric EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller – <=11.06.31
Schneider Electric Saitel DP Remote Terminal Unit & Controller – <=11.06.37
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Unsecured Credentials
Valid Accounts
Credentials in Files
OS Credential Dumping
Account Manipulation
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST SP 800-53 – Authenticator Management
Control ID: IA-5
PCI DSS 4.0 – Secure Storage of Account Data
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 6
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
CISA Zero Trust Maturity Model 2.0 – Identity Management
Control ID: Identity Pillar
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Utilities
Critical infrastructure RTUs with insufficiently protected credentials create unauthorized access risks to power grid operations and SCADA systems nationwide.
Oil/Energy/Solar/Greentech
Energy sector remote terminal units vulnerable to credential exposure threaten operational technology security in oil refineries and renewable energy facilities.
Industrial Automation
Manufacturing control systems using Schneider Electric RTUs face unauthorized access risks through exposed credentials in firmware and system files.
Water and Waste Management
Water treatment facilities utilizing affected RTUs risk unauthorized system compromise through credential vulnerabilities in critical infrastructure control systems.
Sources
- Schneider Electric EasyLogic T150 and Saitel DP RTUhttps://www.cisa.gov/news-events/ics-advisories/icsa-26-181-04Verified
- Schneider Electric Security Notification SEVD-2026-160-02https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-160-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-160-02.pdfVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix Zero Trust CNSF may not prevent the initial credential compromise, it would likely limit the attacker's ability to exploit these credentials to access other workloads.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation would likely limit the attacker's ability to escalate privileges beyond the initially compromised device.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security would likely limit the attacker's ability to move laterally to other critical systems.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control would likely limit the attacker's ability to establish and maintain command and control channels.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement would likely limit the attacker's ability to exfiltrate sensitive data to external servers.
While Aviatrix Zero Trust CNSF may not prevent the initial compromise, it would likely limit the attacker's ability to disrupt operations by altering device configurations.
Impact at a Glance
Affected Business Functions
- Remote Monitoring
- Control Systems
- Data Acquisition
Estimated downtime: 3 days
Estimated loss: $50,000
Operational data and system credentials
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and prevent unauthorized lateral movement.
- • Deploy East-West Traffic Security controls to monitor and restrict internal network communications, mitigating lateral movement.
- • Utilize Egress Security & Policy Enforcement to control outbound traffic and prevent data exfiltration.
- • Apply Multicloud Visibility & Control to detect and respond to anomalous activities across cloud environments.
- • Regularly update and patch firmware to address known vulnerabilities and reduce the risk of exploitation.



