CVE-2026-5667
Received
Received - Intake
Hard-Coded Credentials in Mitsubishi Electric IoT Devices
Publication date: 2026-06-17
Last updated on: 2026-06-17
Assigner: Mitsubishi Electric Corporation
Description
Description
Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Packaged Air Conditioners (for Japan and outside Japan); Refrigerators (for Japan); Heat Pump Water Heaters / HEMS-Compatible Adapters / Wireless LAN Adapters (for Japan); Bathroom Dryer / Heater / Ventilation Systems (for Japan); Adapters for Airflow Ventilation Systems, Heat Pump Chilled / Hot Water Systems, and Ventilation / Air-Conditioning System Air Resorts (for Japan); Lossnay Central Ventilation Systems (for Japan); Smart Switches for Ventilation Fans and Lossnay (for Japan); IH Cooking Heaters (for Japan); and Rice Cookers (for Japan) allows an attacker within Wi-Fi radio range of an affected product to access the affected product using a hard-coded SSID and password, thereby obtaining device data such as operation status, room set temperature, and room temperature; changing the air-conditioner or Wi-Fi settings; or causing Wi-Fi communication to enter a denial-of-service (DoS) condition.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mitsubishi_electric | room_air_conditioner | * |
| mitsubishi_electric | wired_lan_adapter | * |
| mitsubishi_electric | refrigerator | * |
| mitsubishi_electric | heat_pump_water_heater | * |
| mitsubishi_electric | bathroom_dryer | * |
| mitsubishi_electric | lossnay_central_ventilation_system | * |
| mitsubishi_electric | smart_switch | * |
| mitsubishi_electric | ih_cooking_heater | * |
| mitsubishi_electric | rice_cooker | * |
| mitsubishi_electric | room_air_conditioner | 43.00 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-798 | The product contains hard-coded credentials, such as a password or cryptographic key. |