PatchSiren cyber security CVE debrief
CVE-2026-5667 Mitsubishi Electric Corporation CVE debrief
A high-severity vulnerability, CVE-2026-5667, has been disclosed in multiple Mitsubishi Electric devices, including room air conditioners, refrigerators, and heat pump water heaters. An attacker within Wi-Fi radio range can access affected products using a hard-coded SSID and password, potentially obtaining device data, modifying settings, or causing a denial-of-service (DoS) condition. Users of these devices should take immediate action to mitigate the risk. The vulnerability has a CVSS score of 7.2 and is considered high severity. Mitsubishi Electric has released a PDF advisory [ref-5] detailing the vulnerability and mitigation strategies.
- Vendor
- Mitsubishi Electric Corporation
- Product
- Room Air Conditioners (for Japan) MSZ-BKR2223-W
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-17
- Original CVE updated
- 2026-06-17
- Advisory published
- 2026-06-17
- Advisory updated
- 2026-06-17
Who should care
Organizations and individuals using Mitsubishi Electric room air conditioners, refrigerators, heat pump water heaters, and other affected devices should be aware of this vulnerability and take steps to mitigate the risk. This includes administrators of critical infrastructure, building management systems, and home automation systems that incorporate these devices.
Technical summary
CVE-2026-5667 is a Use of Hard-coded Credentials vulnerability in various Mitsubishi Electric devices. An attacker within Wi-Fi radio range can access affected products using a hard-coded SSID and password, allowing them to obtain device data, change settings, or cause a DoS condition. The vulnerability is classified under CWE-798 and has a CVSS vector of CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X.
Defensive priority
High
Recommended defensive actions
- Immediately update device firmware to the latest version, if available.
- Change default passwords and SSIDs on affected devices.
- Implement secure Wi-Fi configurations, such as WPA2 or WPA3.
- Limit access to affected devices to only necessary personnel.
- Monitor device activity for suspicious behavior.
- Consider isolating affected devices on a separate network.
- Regularly review and update device configurations to ensure security best practices are followed.
Evidence notes
The CVE-2026-5667 vulnerability was disclosed by Mitsubishi Electric through their PSIRT (Product Security Incident Response Team) and is listed on the Japan Vulnerability Notes (JVN) website [ref-4]. The vulnerability details are also documented in a PDF advisory released by Mitsubishi Electric [ref-5].
Sources and references
Verified primary and authoritative sources
-
CVE-2026-5667 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-5667
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-5667 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-5667
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://jvn.jp/vu/JVNVU99620284/
-
Source reference
Unverified legacy reference
URL: https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-001_en.pdf
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.