CVE-2026-5667: Information Disclosure, Information Tampering, or Denial-of-Service (DoS) Vulnerability in Multiple Home Appliances
Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Packaged Air Conditioners (for Japan and outside Japan); Refrigerators (for Japan); Heat Pump Water Heaters / HEMS-Compatible Adapters / Wireless LAN Adapters (for Japan); Bathroom Dryer / Heater / Ventilation Systems (for Japan); Adapters for Airflow Ventilation Systems, Heat Pump Chilled / Hot Water Systems, and Ventilation / Air-Conditioning System Air Resorts (for Japan); Lossnay Central Ventilation Systems (for Japan); Smart Switches for Ventilation Fans and Lossnay (for Japan); IH Cooking Heaters (for Japan); and Rice Cookers (for Japan) allows an attacker within Wi-Fi radio range of an affected product to access the affected product using a hard-coded SSID and password, thereby obtaining device data such as operation status, room set temperature, and room temperature; changing the air-conditioner or Wi-Fi settings; or causing Wi-Fi communication to enter a denial-of-service (DoS) condition.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
If the device's wireless LAN (Wi‑Fi) function is not required for operation, disable the wireless LAN/Wi‑Fi feature on the device to prevent access using the hard-coded SSID and password.
Mitsubishi Electric affected products (room air conditioners, wireless LAN adapters for room and packaged air conditioners, refrigerators, heat pump water heaters / HEMS adapters / wireless LAN adapters, bathroom dryer/heater/ventilation systems, adapters for airflow ventilation systems, heat pump chilled/hot water systems, ventilation/air-conditioning system air resorts, Lossnay central ventilation systems, smart switches for ventilation fans and Lossnay, IH cooking heaters, rice cookers) Wireless LAN / Wi‑Fi = disabled - Compensating control
Place affected devices on an isolated network segment (separate VLAN) and apply network ACLs/firewall rules so that only trusted management hosts can reach the devices. Block or isolate the device network from guest or public Wi‑Fi and untrusted networks to reduce exposure to attackers within radio range.
- Operational
If unauthorized access, configuration changes, or DoS conditions are observed or suspected, remove the affected product from the network immediately and investigate. Treat the device as potentially compromised until confirmed otherwise.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5667?
CVE-2026-5667 has a risk rating of 48, indicating a significant security vulnerability.
What vulnerabilities are associated with CVE-2026-5667?
CVE-2026-5667 involves information disclosure, information tampering, and denial-of-service (DoS) vulnerabilities due to the use of hard-coded credentials.
How do I fix CVE-2026-5667?
To mitigate CVE-2026-5667, update the firmware of the affected Mitsubishi Electric appliances and ensure that hard-coded credentials are changed or disabled.
Which products are affected by CVE-2026-5667?
CVE-2026-5667 affects multiple Mitsubishi Electric products including room air conditioners, wireless LAN adapters, and refrigerators.
What should I do if I own a product affected by CVE-2026-5667?
If you own an affected product, it is recommended to check for any available firmware updates from Mitsubishi Electric to address CVE-2026-5667.