VYPR
Unrated severityNVD Advisory· Published Apr 1, 2022· Updated Aug 3, 2024

CVE-2022-25156

CVE-2022-25156

Description

Weak hash in Mitsubishi Electric MELSEC series CPUs lets remote attackers reverse passwords from eavesdropped hashes to log in.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Weak hash in Mitsubishi Electric MELSEC series CPUs lets remote attackers reverse passwords from eavesdropped hashes to log in.

Vulnerability

CVE-2022-25156 is a use of weak hash vulnerability (CWE-328) in Mitsubishi Electric MELSEC iQ-F, iQ-R, Q, and L series CPUs and communication modules, affecting all versions of a wide range of models [1][2]. The affected products use a weak hash algorithm to protect passwords, making it feasible for an attacker to reverse a password from a previously intercepted password hash [2]. The vulnerability exists in the authentication mechanism, where the hash is stored or transmitted instead of the original password.

Exploitation

A remote, unauthenticated attacker can eavesdrop on network traffic to capture a password hash sent or stored by the device [2]. The attacker then reverses the weak hash offline to recover the plaintext password [2][2]. No special privileges or user interaction are required beyond positioning themselves to observe authentication traffic [2].

Impact

Successful exploitation allows the attacker to log in to the affected product using the recovered plaintext password [1][2]. This could lead to disclosure of sensitive information (confidentiality impact) and potentially allow unauthorized control or configuration changes, depending on the attacker's subsequent actions [2].

Mitigation

As of the latest advisories, Mitsubishi Electric has not yet released a firmware fix for this vulnerability [1][2]. Users are advised to contact Mitsubishi Electric support for mitigation measures, and to restrict network access to affected devices, use firewalls, and monitor for suspicious activity [2]. The vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

3

News mentions

0

No linked articles in our index yet.