Back

HIGH

Mitsubishi Electric Europe smartRTU Missing Authentication for Critical Function

Published Dec 24, 2025

Description

A remote unauthenticated attacker may be able to bypass authentication by utilizing a specific API route to execute arbitrary OS commands.

Affected products

Remediation

Vendor solution

Mitsubishi Electric Europe B.V. recommends that users take note of the following mitigation measures to minimize the risk of exploiting this vulnerability:

* Use a firewall or virtual private network (VPN), etc. to prevent unauthorized access when Internet access is required.

* Use within a LAN and block access from untrusted networks and hosts through firewalls.

* Use web application firewall (WAF) to prevent to filter, monitor and block any malicious HTTP/HTTPS traffic.

* Allow web client access from trusted networks only.

For more information, please see Mitsubishi Electric Europe MEU_PSIRT_2025-3128 https://emea.mitsubishielectric.com/fa/products/quality/quality-news-information  under the "Vulnerability Information" section.

Metrics

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Dec 24, 2025
Updated Dec 24, 2025
Reserved Apr 3, 2025
CISA Vulnrichment
Updated Dec 24, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a