PatchSiren cyber security CVE debrief
CVE-2025-3128 Mitsubishi Electric Europe B.V. CVE debrief
CVE-2025-3128 is a critical vulnerability in Mitsubishi Electric Europe B.V. smartRTU affecting versions <=3.37. According to the CISA CSAF advisory, a remote attacker who has bypassed authentication could execute arbitrary OS commands, leading to disclosure, tampering, destruction, deletion of information, or denial of service.
- Vendor
- Mitsubishi Electric Europe B.V.
- Product
- smartRTU
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-04-15
- Original CVE updated
- 2025-05-06
- Advisory published
- 2025-04-15
- Advisory updated
- 2025-05-06
Who should care
Organizations running Mitsubishi Electric smartRTU, especially OT/ICS operators, plant engineers, infrastructure teams, and anyone managing remote or web access to these devices.
Technical summary
The advisory describes a remotely reachable issue in smartRTU where an attacker who has bypassed authentication may execute arbitrary OS commands. The stated impact includes confidentiality, integrity, and availability compromise, and the affected product entry is Mitsubishi Electric Europe B.V. smartRTU: <=3.37. The supplied CSAF content also recommends network access restrictions and web filtering controls as mitigations.
Defensive priority
Immediate: critical remote command execution risk on an OT product with network exposure concerns.
Recommended defensive actions
- Restrict access to smartRTU to trusted networks only.
- Place the device behind a firewall or VPN if Internet access is required.
- Use LAN-only deployment and block untrusted hosts and networks at the perimeter.
- Deploy a web application firewall where applicable to monitor and block malicious HTTP/HTTPS traffic.
- Review Mitsubishi Electric Europe B.V. MEU_PSIRT_2025-3128 guidance referenced in the advisory.
- Verify whether any smartRTU instances are running version 3.37 or earlier and prioritize them for mitigation.
Evidence notes
Facts are drawn from the CISA CSAF advisory ICSA-25-105-09 and its referenced material. The advisory identifies Mitsubishi Electric Europe B.V. smartRTU version <=3.37 as affected, describes the potential for arbitrary OS command execution, and lists network-access mitigations. The source revision history shows the initial publication on 2025-04-15 and a later revision on 2025-05-06 marked as typo fixes only.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-3128 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-3128
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-3128 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-3128
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-105-09.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-105-09
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.