Vulnerability Description
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation G-50 all versions, G-50-W all versions, G-50A all versions, GB-50 all versions, GB-50A all versions, GB-24A all versions, G-150AD all versions, AG-150A-A all versions, AG-150A-J all versions, GB-50AD all versions, GB-50ADA-A all versions, GB-50ADA-J all versions, EB-50GU-A all versions, EB-50GU-J all versions, AE-200J all versions, AE-200A all versions, AE-200E all versions, AE-50J all versions, AE-50A all versions, AE-50E all versions, EW-50J all versions, EW-50A all versions, EW-50E all versions, TE-200A all versions, TE-50A all versions, TW-50A all versions, and CMS-RMD-J all versions allows a remote unauthenticated attacker to bypass authentication and then control the air conditioning systems illegally, or disclose information in them by exploiting this vulnerability. In addition, the attacker may tamper with firmware for them using the disclosed information.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://jvn.jp/vu/JVNVU96471539/
- https://www.cisa.gov/news-events/ics-advisories/icsa-25-177-01
- https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-004_en.pdf
FAQ
What is CVE-2025-3699?
CVE-2025-3699 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation G-50 all versions, G-50-W all versions, G-50A all versions, GB-50 all versions, GB-50A all versions, GB-24...
How severe is CVE-2025-3699?
CVE-2025-3699 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-3699?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.