CVE-2025-3128: Mitsubishi Electric Europe smartRTU OS Command Injection
A remote unauthenticated attacker who has bypassed authentication could execute arbitrary OS commands to disclose, tamper with, destroy or delete information in Mitsubishi Electric smartRTU, or cause a denial-of service condition on the product.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3128?
CVE-2025-3128 is considered critical due to the potential for remote unauthenticated attackers to execute arbitrary OS commands.
How do I fix CVE-2025-3128?
To fix CVE-2025-3128, upgrade the Mitsubishi Electric smartRTU to the latest version beyond 3.37 where a patch is available.
What systems are affected by CVE-2025-3128?
CVE-2025-3128 affects all versions of Mitsubishi Electric smartRTU up to and including version 3.37.
Can CVE-2025-3128 cause a denial-of-service attack?
Yes, CVE-2025-3128 can allow attackers to induce a denial-of-service condition on the Mitsubishi Electric smartRTU.
Is authentication bypass possible with CVE-2025-3128?
Yes, a remote unauthenticated attacker can bypass authentication due to CVE-2025-3128.