CVE-2026-5667: Information Disclosure, Information Tampering, or Denial-of-Service (DoS) Vulnerability in Multiple Home Appliances

Published Jun 17, 2026
·
Updated

Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Packaged Air Conditioners (for Japan and outside Japan); Refrigerators (for Japan); Heat Pump Water Heaters / HEMS-Compatible Adapters / Wireless LAN Adapters (for Japan); Bathroom Dryer / Heater / Ventilation Systems (for Japan); Adapters for Airflow Ventilation Systems, Heat Pump Chilled / Hot Water Systems, and Ventilation / Air-Conditioning System Air Resorts (for Japan); Lossnay Central Ventilation Systems (for Japan); Smart Switches for Ventilation Fans and Lossnay (for Japan); IH Cooking Heaters (for Japan); and Rice Cookers (for Japan) allows an attacker within Wi-Fi radio range of an affected product to access the affected product using a hard-coded SSID and password, thereby obtaining device data such as operation status, room set temperature, and room temperature; changing the air-conditioner or Wi-Fi settings; or causing Wi-Fi communication to enter a denial-of-service (DoS) condition.

Affected Software

15 affected components
Mitsubishi Electric Room Air Conditioners
Mitsubishi Electric Wireless LAN Adapters for Room Air Conditioners
Mitsubishi Electric Wireless LAN Adapters for Packaged Air Conditioners
Mitsubishi Electric Refrigerators
Mitsubishi Electric Heat Pump Water Heaters
Mitsubishi Electric HEMS-Compatible Adapters
Mitsubishi Electric Wireless LAN Adapters (Heat Pump Water Heaters)
Mitsubishi Electric Bathroom Dryer / Heater / Ventilation Systems
Mitsubishi Electric Adapter for Airflow Ventilation Systems
Mitsubishi Electric Heat Pump Chilled / Hot Water Systems
Mitsubishi Electric Ventilation / Air-Conditioning System Air Resorts
Mitsubishi Electric Lossnay Central Ventilation Systems
Mitsubishi Electric Smart Switches for Ventilation Fans and Lossnay
Mitsubishi Electric IH Cooking Heaters
Mitsubishi Electric Rice Cookers

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    If the device's wireless LAN (Wi‑Fi) function is not required for operation, disable the wireless LAN/Wi‑Fi feature on the device to prevent access using the hard-coded SSID and password.

    Mitsubishi Electric affected products (room air conditioners, wireless LAN adapters for room and packaged air conditioners, refrigerators, heat pump water heaters / HEMS adapters / wireless LAN adapters, bathroom dryer/heater/ventilation systems, adapters for airflow ventilation systems, heat pump chilled/hot water systems, ventilation/air-conditioning system air resorts, Lossnay central ventilation systems, smart switches for ventilation fans and Lossnay, IH cooking heaters, rice cookers) Wireless LAN / Wi‑Fi = disabled
  2. Compensating control

    Place affected devices on an isolated network segment (separate VLAN) and apply network ACLs/firewall rules so that only trusted management hosts can reach the devices. Block or isolate the device network from guest or public Wi‑Fi and untrusted networks to reduce exposure to attackers within radio range.

  3. Operational

    If unauthorized access, configuration changes, or DoS conditions are observed or suspected, remove the affected product from the network immediately and investigate. Treat the device as potentially compromised until confirmed otherwise.

Event History

Jun 17, 2026
CVE Published
via MITRE·10:53 AM
Data Sourced
via MITRE·10:53 AM
DescriptionWeakness
Data Sourced
via NVD·01:20 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-5667?

CVE-2026-5667 has a risk rating of 48, indicating a significant security vulnerability.

2

What vulnerabilities are associated with CVE-2026-5667?

CVE-2026-5667 involves information disclosure, information tampering, and denial-of-service (DoS) vulnerabilities due to the use of hard-coded credentials.

3

How do I fix CVE-2026-5667?

To mitigate CVE-2026-5667, update the firmware of the affected Mitsubishi Electric appliances and ensure that hard-coded credentials are changed or disabled.

4

Which products are affected by CVE-2026-5667?

CVE-2026-5667 affects multiple Mitsubishi Electric products including room air conditioners, wireless LAN adapters, and refrigerators.

5

What should I do if I own a product affected by CVE-2026-5667?

If you own an affected product, it is recommended to check for any available firmware updates from Mitsubishi Electric to address CVE-2026-5667.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203