CVE-2025-3699: Critical severity Mitsubishi Electric G-50 vulnerability
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation G-50 all versions, G-50-W all versions, G-50A all versions, GB-50 all versions, GB-50A all versions, GB-24A all versions, G-150AD all versions, AG-150A-A all versions, AG-150A-J all versions, GB-50AD all versions, GB-50ADA-A all versions, GB-50ADA-J all versions, EB-50GU-A all versions, EB-50GU-J all versions, AE-200J all versions, AE-200A all versions, AE-200E all versions, AE-50J all versions, AE-50A all versions, AE-50E all versions, EW-50J all versions, EW-50A all versions, EW-50E all versions, TE-200A all versions, TE-50A all versions, TW-50A all versions, and CMS-RMD-J all versions allows a remote unauthenticated attacker to bypass authentication and then control the air conditioning systems illegally, or disclose information in them by exploiting this vulnerability. In addition, the attacker may tamper with firmware for them using the disclosed information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3699?
The severity of CVE-2025-3699 is categorized as critical due to missing authentication for critical functions.
How do I fix CVE-2025-3699?
To fix CVE-2025-3699, update affected Mitsubishi Electric products to the latest version provided by the vendor.
What products are affected by CVE-2025-3699?
Affected products include Mitsubishi Electric G-50, G-50-W, G-50A, GB-50, GB-50A, GB-24A, G-150AD and others prior to specified versions.
What are the potential risks associated with CVE-2025-3699?
The potential risks associated with CVE-2025-3699 include unauthorized remote access and control of critical functions.
How can I verify if my device is vulnerable to CVE-2025-3699?
You can verify if your device is vulnerable to CVE-2025-3699 by checking the product version against the list of affected versions.