PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-3128 Mitsubishi Electric Europe B.V. CVE debrief

CVE-2025-3128 is a critical vulnerability in Mitsubishi Electric Europe B.V. smartRTU affecting versions <=3.37. According to the CISA CSAF advisory, a remote attacker who has bypassed authentication could execute arbitrary OS commands, leading to disclosure, tampering, destruction, deletion of information, or denial of service.

Vendor
Mitsubishi Electric Europe B.V.
Product
smartRTU
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2025-04-15
Original CVE updated
2025-05-06
Advisory published
2025-04-15
Advisory updated
2025-05-06

Who should care

Organizations running Mitsubishi Electric smartRTU, especially OT/ICS operators, plant engineers, infrastructure teams, and anyone managing remote or web access to these devices.

Technical summary

The advisory describes a remotely reachable issue in smartRTU where an attacker who has bypassed authentication may execute arbitrary OS commands. The stated impact includes confidentiality, integrity, and availability compromise, and the affected product entry is Mitsubishi Electric Europe B.V. smartRTU: <=3.37. The supplied CSAF content also recommends network access restrictions and web filtering controls as mitigations.

Defensive priority

Immediate: critical remote command execution risk on an OT product with network exposure concerns.

Recommended defensive actions

  • Restrict access to smartRTU to trusted networks only.
  • Place the device behind a firewall or VPN if Internet access is required.
  • Use LAN-only deployment and block untrusted hosts and networks at the perimeter.
  • Deploy a web application firewall where applicable to monitor and block malicious HTTP/HTTPS traffic.
  • Review Mitsubishi Electric Europe B.V. MEU_PSIRT_2025-3128 guidance referenced in the advisory.
  • Verify whether any smartRTU instances are running version 3.37 or earlier and prioritize them for mitigation.

Evidence notes

Facts are drawn from the CISA CSAF advisory ICSA-25-105-09 and its referenced material. The advisory identifies Mitsubishi Electric Europe B.V. smartRTU version <=3.37 as affected, describes the potential for arbitrary OS command execution, and lists network-access mitigations. The source revision history shows the initial publication on 2025-04-15 and a later revision on 2025-05-06 marked as typo fixes only.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-3128 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-3128

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-3128 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-3128

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-105-09.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-105-09

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.