PT-2025-27019 · Mitsubishi · G-50-W+26
Mihály Csonka
·
Published
2025-06-26
·
Updated
2025-12-23
·
CVE-2025-3699
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Mitsubishi Electric Corporation G-50 versions 3.37 and prior
Mitsubishi Electric Corporation G-50-W versions 3.37 and prior
Mitsubishi Electric Corporation G-50A versions 3.37 and prior
Mitsubishi Electric Corporation GB-50 versions 3.37 and prior
Mitsubishi Electric Corporation GB-50A versions 3.37 and prior
Mitsubishi Electric Corporation GB-24A versions 9.12 and prior
Mitsubishi Electric Corporation G-150AD versions 3.21 and prior
Mitsubishi Electric Corporation AG-150A-A versions 3.21 and prior
Mitsubishi Electric Corporation AG-150A-J versions 3.21 and prior
Mitsubishi Electric Corporation GB-50AD versions 3.21 and prior
Mitsubishi Electric Corporation GB-50ADA-A versions 3.21 and prior
Mitsubishi Electric Corporation GB-50ADA-J versions 3.21 and prior
Mitsubishi Electric Corporation EB-50GU-A versions 7.11 and prior
Mitsubishi Electric Corporation EB-50GU-J versions 7.11 and prior
Mitsubishi Electric Corporation AE-200J versions 8.01 and prior
Mitsubishi Electric Corporation AE-200A versions 8.01 and prior
Mitsubishi Electric Corporation AE-200E versions 8.01 and prior
Mitsubishi Electric Corporation AE-50J versions 8.01 and prior
Mitsubishi Electric Corporation AE-50A versions 8.01 and prior
Mitsubishi Electric Corporation AE-50E versions 8.01 and prior
Mitsubishi Electric Corporation EW-50J versions 8.01 and prior
Mitsubishi Electric Corporation EW-50A versions 8.01 and prior
Mitsubishi Electric Corporation EW-50E versions 8.01 and prior
Mitsubishi Electric Corporation TE-200A versions 8.01 and prior
Mitsubishi Electric Corporation TE-50A versions 8.01 and prior
Mitsubishi Electric Corporation TW-50A versions 8.01 and prior
Mitsubishi Electric Corporation CMS-RMD-J versions 1.40 and prior
Description:
The issue allows a remote unauthenticated attacker to bypass authentication and then control the air conditioning systems illegally, or disclose information in them by exploiting this vulnerability. In addition, the attacker may tamper with firmware for them using the disclosed information.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ae-200A
Ae-200E
Ae-200J
Ae-50A
Ae-50E
Ae-50J
Ag-150A-A
Ag-150A-J
Cms-Rmd-J
Eb-50Gu-A
Eb-50Gu-J
Ew-50A
Ew-50E
Ew-50J
G-150Ad
G-50
G-50-W
G-50A
Gb-24A
Gb-50
Gb-50A
Gb-50Ad
Gb-50Ada-A
Gb-50Ada-J
Te-200A
Te-50A
Tw-50A