A severe authentication bypass vulnerability (CVE-2025-3699) has been discovered in multiple Mitsubishi Electric air conditioning systems, allowing unauthenticated attackers to remotely control units and compromise building climate systems.
Rated 9.8 on the CVSS v3.1 scale (9.3 under CVSS v4), the flaw impacts controllers across commercial facilities globally, enabling illegal system manipulation, data theft, and firmware tampering.
Mitsubishi Electric confirmed the vulnerability on June 26, 2025, warning that improperly configured systems exposed to external networks face immediate risk.
Technical Mechanism and Attack Vectors
The vulnerability stems from a Missing Authentication for Critical Function (CWE-306) in the web interfaces of affected controllers.
Attackers can bypass authentication entirely without user interaction, leveraging network-based attacks (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Successful exploitation enables:
- Unauthorized control of HVAC operations (temperature, fan speed, modes).
- Theft of sensitive system data and configuration files.
- Firmware tampering using disclosed information.
The flaw is exploitable remotely when systems are connected directly to the internet without a VPN or network segmentation.
Affected Products and Deployment Risks
Over 30 controller models are vulnerable, including:
| Product Series | Vulnerable Firmware Versions |
|---|---|
| G-50, G-50A, GB-series | ≤3.37 |
| AE-200, AE-50, EW-series | ≤8.01 |
| CMS-RMD-J | ≤1.40 |
| Industrial and commercial deployments in sectors like data centers, hospitals, and office complexes are at the highest risk. Mitsubishi Electric emphasizes that systems operating in secured intranets or behind VPNs (System Examples 1-2) remain protected, but internet-exposed units (System Example 3) are critically vulnerable. |
Mitigation Strategies and Patch Timeline
No patches exist for most models, though Mitsubishi Electric is preparing updates for AE/EW/TE/TW-series controllers.
Recommended mitigations include:
- Network hardening: Restrict access via firewalls; isolate controllers in VLANs or behind VPNs.
- Physical security: Lock server rooms and HVAC control panels.
- Endpoint protection: Update OS/browsers and deploy antivirus on management workstations.
Security researcher Mihály Csonka identified the flaw, prompting coordinated disclosures with CISA and Mitsubishi Electric. - Administrators must audit configurations immediately, prioritizing internet-facing systems.
This critical vulnerability underscores the convergence of OT and IT security risks in building management systems.
With no widespread patches available, network segmentation and access controls form the primary defense against potential HVAC sabotage or data exfiltration.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant updates