VYPR
Unrated severityNVD Advisory· Published Mar 16, 2020· Updated Aug 4, 2024

CVE-2020-5546

CVE-2020-5546

Description

Argument injection in Mitsubishi Electric MELQIC IU1 series firmware allows network-adjacent attackers to stop network functions or execute malware.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Argument injection in Mitsubishi Electric MELQIC IU1 series firmware allows network-adjacent attackers to stop network functions or execute malware.

Vulnerability

An improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability exists in the TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier [1]. This CWE-88 vulnerability allows an attacker on the same network segment to inject arguments into a command executed by the device's TCP/IP stack via a specially crafted packet [1].

Exploitation

An attacker on the same network segment as the affected device can send a specially crafted packet to trigger the argument injection [1]. The attacker does not require authentication, only network access to the device [1]. The attack vector is network-based, exploiting the TCP function without any user interaction [1].

Impact

Successful exploitation allows the attacker to stop the network functions of the device or execute malware [1]. This could lead to denial of service or arbitrary code execution, compromising the confidentiality, integrity, and availability of the device and potentially the network it serves [1]. The attacker gains the ability to disrupt operations or deploy malicious software on the affected hardware [1].

Mitigation

The fixed firmware version is 1.08 or later, which should be applied using IU Configuration Tool version 1.04 or later [1]. As a workaround, restricting access to the network from untrusted hosts and networks can mitigate the risk [1]. No public KEV listing or EOL status is mentioned in the references.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

0

No linked articles in our index yet.