CVE-2026-9650: Credential Exposure in Schneider Electric EasyLogic T150 and Saitel DP
CVE-2026-9650 is a credential storage vulnerability affecting Schneider Electric industrial control devices. Attackers can read poorly protected credentials directly from firmware or system files without needing to authenticate first. Once an attacker obtains these credentials, they can use them to compromise the device—though the vulnerability description notes this requires physical access to the device itself. The vulnerability carries a HIGH severity rating due to the potential for unauthorized system access and sensitive data exposure.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.5 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Weaknesses (CWE)
- CWE-522
- Affected products
- 4 configuration(s)
- Published / Modified
- 2026-06-25 / 2026-07-14
NVD description (verbatim)
CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenticated attacker accesses credentials stored within firmware or system files. With this credential an attacker could subsequently compromise the device if they have physical access to the device.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
This vulnerability is classified as CWE-522 (Insufficiently Protected Credentials). The flaw allows unauthenticated network access to retrieve credentials that are inadequately protected within device firmware or system files. The CVSS 3.1 vector (7.5/HIGH) reflects high confidentiality impact with network-based attack capability, no authentication required, and low attack complexity. The credential exposure itself is the primary risk vector; subsequent device compromise depends on the attacker obtaining physical access to the affected hardware.
Business impact
Exposed credentials create pathways for attackers to gain control of critical industrial control equipment. For organizations relying on Schneider Electric EasyLogic T150 or Saitel DP devices, this vulnerability could lead to unauthorized access, operational disruption, and potential manipulation of industrial processes. The impact is magnified in critical infrastructure sectors (energy, water, manufacturing) where device availability and integrity directly affect business continuity.
Affected systems
This vulnerability affects Schneider Electric EasyLogic T150 (both the device and its firmware) and Schneider Electric Saitel DP (device and firmware). Organizations should inventory instances of these products across their infrastructure, including both current deployments and archived or backup units, as any device running vulnerable firmware remains a potential attack vector.
Exploitability
The vulnerability is exploitable over the network without requiring authentication or user interaction, which is why the CVSS score is elevated despite the physical-access requirement for full device compromise. An attacker can retrieve credentials remotely; however, using those credentials to actively compromise the device typically requires physical proximity or network connectivity to the device itself. The lack of KEV status indicates it is not yet publicly documented as exploited in the wild, but the straightforward nature of credential extraction (no authentication barrier) means exploitation could be weaponized relatively quickly if detailed technical information becomes public.
Remediation
Patch vulnerable firmware immediately. Verify available firmware updates from Schneider Electric for both EasyLogic T150 and Saitel DP products. In parallel, implement network segmentation to restrict access to these devices from untrusted networks and change any credentials that may have been exposed. Consider deploying additional monitoring on affected devices to detect unauthorized access attempts.
Patch guidance
Check the Schneider Electric security advisory and product support portal for patched firmware versions specific to EasyLogic T150 and Saitel DP. Firmware updates should be applied in a controlled maintenance window given the industrial control nature of these devices. Verify patch applicability for your specific device models and firmware versions before deployment. Test patches in a non-production environment first to ensure no operational impact.
Detection guidance
Monitor network traffic to and from EasyLogic T150 and Saitel DP devices for unusual authentication patterns or credential-related API calls. Review device logs and firmware access logs for evidence of credential file reads. Network intrusion detection systems should flag any suspicious queries to device configuration or firmware directories. If credentials are suspected compromised, monitor downstream systems for login attempts using exposed credentials.
Why prioritize this
Despite not being listed on the KEV catalog, this vulnerability merits high priority due to its HIGH severity rating, network-exploitable nature, and targeting of industrial control devices critical to infrastructure operations. The zero-authentication requirement for credential extraction and the direct pathway to system compromise make this a significant risk. Organizations should treat this as urgent, especially if EasyLogic T150 or Saitel DP devices are deployed in production environments.
Risk score, explained
The CVSS 3.1 score of 7.5/HIGH reflects a network-based attack vector with low complexity, no authentication needed, and high confidentiality impact. Although the description mentions physical access as a precondition for full device compromise, the credential exposure itself is a standalone, remotely exploitable risk that warrants the elevated score. The vulnerability does not directly cause integrity or availability loss (hence no impact in those categories), but the exposed credentials serve as a stepping stone for further attacks.
Frequently asked questions
Do we need physical access to exploit this vulnerability?
The credential extraction itself is exploitable remotely without physical access. However, the vulnerability description notes that using those credentials to fully compromise the device may require physical proximity. Regardless, the credential exposure is a serious risk on its own and should be remediated immediately.
Is this vulnerability actively exploited in the wild?
No, the vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog as of now. However, the straightforward nature of the vulnerability and the public disclosure means attackers could develop exploits relatively quickly. Do not rely on lack of current exploitation to delay patching.
What should we do if we suspect our credentials have been exposed?
Change all credentials for affected devices immediately, monitor downstream systems for unauthorized login attempts using those credentials, and review device and system logs for evidence of unauthorized access. Apply security patches as soon as possible and implement network segmentation if the devices are exposed to untrusted networks.
Are there any workarounds if we cannot patch immediately?
While patching is the primary remediation, you can reduce risk by restricting network access to affected devices through firewall rules or network segmentation, disabling remote management features if not required, and increasing monitoring and alerting for suspicious activity on and around these devices.
This analysis is provided for informational purposes to help security professionals understand and respond to CVE-2026-9650. Verify all patch versions, vendor guidance, and affected product details directly with Schneider Electric before taking remediation action. The information herein reflects the state of vulnerability data at publication; threat landscape and vendor guidance may evolve. SEC.co does not provide legal, compliance, or operational advice; consult your organization's security and legal teams for decisions specific to your environment. Source: NVD (public-domain), retrieved 2026-08-03. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-53840HIGHOpenClaw MCP Header Leakage Vulnerability (CVSS 7.1)
- CVE-2026-7313HIGHProgress Sitefinity Plaintext Credential Exposure (CVSS 8.7)
- CVE-2024-45636MEDIUMIBM QRadar EDR Plaintext Credential Storage (3.12–3.12.24)
- CVE-2026-32315MEDIUMmotionEye Configuration File Permissions Exposure (Medium)
- CVE-2026-39908MEDIUMOpenBullet2 NTLMv2 Hash Disclosure via UNC Proxy Path
- CVE-2026-41715MEDIUMReactor Netty HTTP Redirect Credential Leakage Vulnerability
- CVE-2026-42951MEDIUMMacGregor VDR G4E Backup Credential Disclosure – Patch Guidance
- CVE-2026-49379MEDIUMJetBrains TeamCity Credential Exposure in Thread Names