Mitsubishi Electric Europe smartRTU OS Command Injection
Vulnerability Description
A remote unauthenticated attacker who has bypassed authentication could execute arbitrary OS commands to disclose, tamper with, destroy or delete information in Mitsubishi Electric smartRTU, or cause a denial-of service condition on the product.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-3128
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Noam Moshe of Claroty Team82 reported this vulnerability to CISA.
References
More from Mitsubishi Electric Europe
View All →Affected Vendor
Mitsubishi Electric Europe
View all reports →