A vulnerability classified as critical was found in Hitachi Energy MicroSCADA X SYS600 up to 10.6. This vulnerability affects unknown code of the component Notify Service. The manipulation leads to incorrect default permissions.

This vulnerability was named CVE-2025-39201. The attack needs to be approached locally. There is no exploit available.