Two Open-Source Bugs Force Patch for Hitachi Energy's REB500 Grid Relay

A pair of flaws in a widely used XML parser could let an insider knock Hitachi Energy's protection relay offline. The fix is version 8.3.4.0.

ThreatVectr NewsdeskAI-assistedPublished · Editor: Lee Brown· 3 min read
Illustration: a high-voltage electrical substation at dusk, rows of grey insulators and steel lattice towers
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Hitachi Energy's REB500, a protection relay used inside electrical substations worldwide, is affected by two flaws in a shared open-source component through version 8.3.3.1, with a fix released in 8.3.4.0.
  • Both bugs, CVE-2024-8176 and CVE-2025-59375, sit in libexpat, an XML parsing library bundled into the relay's IEC 61850 substation messaging feature.
  • Both carry a vendor CVSS score of 6.5, because an attacker needs valid login credentials and local network access before either flaw is reachable.
  • CISA republished the advisory on 6 October 2026, converting it directly from Hitachi Energy's own PSIRT disclosure.
  • Exploitation causes a denial of service; memory corruption is possible in some environments but is not the primary published impact.

Hitachi Energy has told customers to update its REB500 busbar protection relay after two flaws turned up in a piece of open-source code buried inside the product.

The REB500 is not consumer kit. It sits in electrical substations and decides, in milliseconds, whether to trip a circuit when something goes wrong on the grid. Switzerland-based Hitachi Energy sells it worldwide into the energy sector.

The two flaws are in libexpat, a small library that reads XML, the structured text format used by countless programs to swap data. REB500 pulls libexpat in through its support for IEC 61850, the standard messaging protocol substations use to talk to each other. It's a common pattern: a vendor ships a product, a third-party library travels inside it, and years later an advisory lands.

What can an attacker actually do?

Crash the relay. That's the honest answer. An attacker who already holds a valid account and local network access can send a specially built IEC 61850 message that either forces the parser into runaway recursion or tricks it into grabbing huge amounts of memory from a tiny input.

CVE-2024-8176 is a stack overflow triggered by deeply nested XML. CVE-2025-59375 lets a small document balloon into a large memory allocation. Both end the same way: the service falls over. Hitachi Energy notes that memory corruption is possible in some environments, which keeps the door open to something nastier, but the published impact is denial of service.

Translated: an insider, or anyone who has stolen an insider's password, could knock a protection relay offline. In a substation, that's not a small thing.

Who needs to do what?

Anyone running REB500 at version 8.3.3.1 or earlier should move to version 8.3.4.0, which contains the vendor fix for both issues. There's no workaround that patches the flaw itself.

Hitachi Energy and CISA both lean on the standard substation hygiene list: keep control systems off the public internet, put them behind a firewall, separate them from the office network, and use a VPN with current patches if remote access is genuinely needed. None of that removes the bug. It just makes it harder for an outsider to reach the login prompt.

Two practical notes. Both flaws require authentication, so strong password discipline and multi-factor authentication on engineering accounts materially cut the risk. MFA won't patch the parser, but it raises the bar for an attacker who has only phished a credential. The vulnerabilities were found by Hitachi Energy's own internal team, so there's no public exploit code attached to the disclosure as of the republication date.

Should you worry?

This is a routine supply-chain patch story with an uncomfortable setting, and it fits a pattern we've tracked across 30 ICS advisories in the last 90 days. Libexpat travels inside a lot of products, and vendors are going to keep finding it in places that surprise them as they work through their software inventories. The REB500 case is a reminder that an open-source XML parser bug doesn't stay in a web app. It ends up in kit that keeps the lights on, and the patch cycle for a substation relay is measured in planned outages, not Tuesday afternoons.

© 2026 Threat Vectr