Mitsubishi Electric smartRTU Missing Authentication Vulnerability Allowing OS Command Injection

Vulnerability

A vulnerability exists in Mitsubishi Electric smartRTU versions through 3.37, allowing remote unauthenticated attackers to bypass authentication and execute arbitrary operating system commands. This could lead to unauthorized disclosure, modification, destruction, or deletion of information within the product, or cause a denial-of-service condition.

Impact

Exploitation of this vulnerability could allow a remote unauthenticated attacker to execute arbitrary OS commands, potentially leading to unauthorized information disclosure, modification, destruction, or deletion, or causing a denial-of-service condition on the product.

Remediation

Mitsubishi Electric Europe B.V. recommends users take defensive measures to minimize the risk of exploitation. This includes using a firewall or VPN to prevent unauthorized access, blocking access from untrusted networks and hosts, using a web application firewall to filter and monitor malicious HTTP/HTTPS traffic, and allowing web client access from trusted networks only. For more information, consult the Mitsubishi Electric Europe PSIRT vulnerability report MEU_PSIRT_2025-3128.

Added: Dec 24, 2025, 8:19 PM
Updated: Dec 24, 2025, 8:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
7.5
exploitability
7.0
remediation
7.9
relevance
1.5
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.