VYPR

smartRTU

by Mitsubishielectric

CVEs (3)

  • CVE-2025-3128CriAug 21, 2025
    risk 0.64cvss 9.8epss 0.01

    A remote unauthenticated attacker who has bypassed authentication could execute arbitrary OS commands to disclose, tamper with, destroy or delete information in Mitsubishi Electric smartRTU, or cause a denial-of service condition on the product.

  • CVE-2018-16060HigOct 15, 2021
    risk 0.53cvss 7.5epss 0.20

    Mitsubishi Electric Europe B.V. SmartRTU devices allow remote attackers to obtain sensitive information (directory listing and source code) via a direct request to the /web URI.

  • CVE-2018-16061MedOct 15, 2021
    risk 0.43cvss 6.1epss 0.04

    Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php.