CVE-2025-3128

Severity CVSS v4.0:
CRITICAL
Type:
CWE-78 OS Command Injections
Publication date:
21/08/2025
Last modified:
22/08/2025

Description

A remote unauthenticated attacker who has bypassed authentication could <br /> execute arbitrary OS commands to disclose, tamper with, destroy or <br /> delete information in Mitsubishi Electric smartRTU, or cause a denial-of<br /> service condition on the product.