CVE-2025-3232: Mitsubishi Electric Europe smartRTU Missing Authentication for Critical Function
Published Dec 24, 2025
·Updated
A remote unauthenticated attacker may be able to bypass authentication by utilizing a specific API route to execute arbitrary OS commands.
Affected Software
1 affected component
: Mitsubishi Electric Europe B.V. smartRTU<=3.37
Event History
Aug 21, 2025
Data Sourced
via ICS·07:46 PM
SeverityWeaknessAffected Software
Dec 24, 2025
CVE Published
via MITRE·07:55 PM
Data Sourced
via MITRE·07:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-3232?
CVE-2025-3232 is considered a high severity vulnerability due to its potential for remote code execution without authentication.
2
How do I fix CVE-2025-3232?
To mitigate CVE-2025-3232, update Mitsubishi Electric smartRTU to the latest version beyond 3.37.
3
What type of attack is CVE-2025-3232 associated with?
CVE-2025-3232 is associated with remote unauthenticated attacks that can bypass authentication.
4
What is affected by CVE-2025-3232?
CVE-2025-3232 affects Mitsubishi Electric smartRTU versions up to and including 3.37.
5
Can CVE-2025-3232 allow arbitrary command execution?
Yes, CVE-2025-3232 allows an attacker to execute arbitrary OS commands via a specific API route.