top of page
perceptive_background_267k.jpg

Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electrics Products

Published:

18 December 2025 at 12:00:00

Alert date:

18 December 2025 at 18:04:12

Source:

cisa.gov

Click to open the original link from this advisory

A critical OS command injection vulnerability (CVE-2025-11774) affects Mitsubishi Electric's GENESIS64, ICONICS Suite, MobileHMI, and MC Works64 products. The vulnerability exists in the software keyboard function and could allow attackers to execute arbitrary executable files when legitimate users use the keypad function. Successful exploitation could result in denial-of-service, information tampering, and information disclosure. The vulnerability has a CVSS score of 8.2 (HIGH). Mitsubishi Electric recommends upgrading to GENESIS64 v10.97.3 or higher, or migrating to GENESIS V11. No fix is planned for MC Works64, with users advised to upgrade to GENESIS64.

Technical details

Mitigation steps:

Affected products:

GENESIS64
ICONICS Suite
MobileHMI
MC Works64

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page