ics-otregulatorNewsThe Broadside1 min read

Schneider Electric fixes EasyLogic T150, Saitel DP RTU credential flaws

The fix is firmware and a reboot, which is never a clerical task for remote operational technology gear.


TL;DR

The Cybersecurity and Infrastructure Security Agency published ICSA-26-181-04 for Schneider Electric EasyLogic T150, formerly Saitel DR, and Saitel DP remote terminal units. CVE-2026-9650 exposes stored credentials to unauthenticated access and carries a Common Vulnerability Scoring System v3.1 score of 7.5; CVE-2026-9651 can disclose password hashes to a privileged local attacker. Critical manufacturing and energy operators, including contractors and managed service providers, should move to EasyLogic T150 11.06.32 or Saitel DP 11.06.38. Both fixes require a reboot and Schneider says to contact Customer Care for the firmware.

CISA's advisory is routine; the operational constraint sits in the remediation line. CVE-2026-9650 gets the 7.5 Common Vulnerability Scoring System v3.1 score because unauthenticated access can expose credentials stored in firmware or system files, and Schneider says those credentials could later support device compromise if the attacker has physical access. CVE-2026-9651 is narrower, requiring privileged local access to read improperly protected system files and disclose password hashes. The Monday work is inventory, firmware acquisition and maintenance planning: EasyLogic T150 moves to 11.06.32, Saitel DP moves to 11.06.38, and both updates require a reboot. The advisory tells customers to contact Schneider Electric's Customer Care Center for the firmware; it does not make the deployment window any easier for energy or critical manufacturing RTUs.


Published ·Deep Fathom