CVE Tools
Back to feed
Exploited in the wild FortiGate ics-ot-iot RUTX50 Fortinet data-breach

Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

The Hacker News·By The Hacker News··5 min read
CVE Tools coverage

CERT Polska has disclosed that attackers disrupted operations at a Polish combined heat and power plant by compromising its industrial control systems through a private cellular access point name (APN). The intrusion exploited a misconfigured Teltonika RUTX50 router and a WAGO PFC200 controller with default credentials, allowing threat actors to pivot from a wind farm network to disable steam turbines and water treatment processes. Although no specific CVE was identified as the root cause, the incident highlights critical vulnerabilities in the Fortinet FortiGate firewall's VPN exposure and the lack of segmentation in OT networks, marking the first known real-world attack leveraging this specific cellular vector.