A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update, if secure update feature was not enabled on all CMUs of a RTU500. If a malicious actor successfully exploits this vulnerability, they could use it to update the RTU500 with unsigned firmware.
https://www.cisa.gov/news-events/ics-advisories/icsa-25-023-02
https://publisher.hitachienergy.com/preview?DocumentId=8DBD000199&languageCode=en&Preview=true