PT-2025-27019 · Mitsubishi · G-50-W+26

Mihály Csonka

·

Published

2025-06-26

·

Updated

2025-12-23

·

CVE-2025-3699

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Mitsubishi Electric Corporation G-50 versions 3.37 and prior Mitsubishi Electric Corporation G-50-W versions 3.37 and prior Mitsubishi Electric Corporation G-50A versions 3.37 and prior Mitsubishi Electric Corporation GB-50 versions 3.37 and prior Mitsubishi Electric Corporation GB-50A versions 3.37 and prior Mitsubishi Electric Corporation GB-24A versions 9.12 and prior Mitsubishi Electric Corporation G-150AD versions 3.21 and prior Mitsubishi Electric Corporation AG-150A-A versions 3.21 and prior Mitsubishi Electric Corporation AG-150A-J versions 3.21 and prior Mitsubishi Electric Corporation GB-50AD versions 3.21 and prior Mitsubishi Electric Corporation GB-50ADA-A versions 3.21 and prior Mitsubishi Electric Corporation GB-50ADA-J versions 3.21 and prior Mitsubishi Electric Corporation EB-50GU-A versions 7.11 and prior Mitsubishi Electric Corporation EB-50GU-J versions 7.11 and prior Mitsubishi Electric Corporation AE-200J versions 8.01 and prior Mitsubishi Electric Corporation AE-200A versions 8.01 and prior Mitsubishi Electric Corporation AE-200E versions 8.01 and prior Mitsubishi Electric Corporation AE-50J versions 8.01 and prior Mitsubishi Electric Corporation AE-50A versions 8.01 and prior Mitsubishi Electric Corporation AE-50E versions 8.01 and prior Mitsubishi Electric Corporation EW-50J versions 8.01 and prior Mitsubishi Electric Corporation EW-50A versions 8.01 and prior Mitsubishi Electric Corporation EW-50E versions 8.01 and prior Mitsubishi Electric Corporation TE-200A versions 8.01 and prior Mitsubishi Electric Corporation TE-50A versions 8.01 and prior Mitsubishi Electric Corporation TW-50A versions 8.01 and prior Mitsubishi Electric Corporation CMS-RMD-J versions 1.40 and prior
Description: The issue allows a remote unauthenticated attacker to bypass authentication and then control the air conditioning systems illegally, or disclose information in them by exploiting this vulnerability. In addition, the attacker may tamper with firmware for them using the disclosed information.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Weakness Enumeration

Related Identifiers

BDU:2026-00131
CVE-2025-3699

Affected Products

Ae-200A
Ae-200E
Ae-200J
Ae-50A
Ae-50E
Ae-50J
Ag-150A-A
Ag-150A-J
Cms-Rmd-J
Eb-50Gu-A
Eb-50Gu-J
Ew-50A
Ew-50E
Ew-50J
G-150Ad
G-50
G-50-W
G-50A
Gb-24A
Gb-50
Gb-50A
Gb-50Ad
Gb-50Ada-A
Gb-50Ada-J
Te-200A
Te-50A
Tw-50A