A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A session identifier is generated using an algorithm with insufficient randomness, resulting in a token with low entropy that can be predicted or brute-forced within a feasible number of attempts. This could allow an unauthenticated remote attacker to derive valid session identifiers and bypass authentication.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-62646 exposes a critical authentication bypass vulnerability in Reyrolle 7SR5 protective relays through insufficient entropy in session identifier generation. The vulnerability allows unauthenticated remote attackers to predict or brute-force valid session tokens, completely circumventing the device's authentication mechanisms. This affects industrial control systems and power distribution infrastructure relying on these relays for operational safety—organizations managing critical power systems, utilities, and industrial facilities face direct risk of unauthorized access leading to potential system compromise, data exfiltration, and operational disruption.
While MITRE ATT&CK techniques are not formally mapped to this CVE, Casky's 754 security skills enable Claude AI to detect the attack patterns underlying weak session generation through extended reasoning. Practitioners would identify findings related to T1110 (Brute Force) reconnaissance attempts showing repetitive authentication requests with algorithmically predictable patterns, T1528 (Steal Valid Session Identifiers) tactics where session tokens cluster around predictable ranges, and T1199 (Trusted Relationship) exploitation where compromised sessions enable lateral movement within industrial networks. Casky's Claude-powered analysis would surface anomalous token entropy metrics, failed authentication attempts following mathematical sequences, and session validation failures that deviate from random distribution—indicators that practitioners can correlate with their device logs to confirm exploitation and implement immediate mitigation through V2.70+ upgrades.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-62646. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation