CVE-2026-5667
Received Received - Intake
Hard-Coded Credentials in Mitsubishi Electric IoT Devices

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: Mitsubishi Electric Corporation

Description
Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Packaged Air Conditioners (for Japan and outside Japan); Refrigerators (for Japan); Heat Pump Water Heaters / HEMS-Compatible Adapters / Wireless LAN Adapters (for Japan); Bathroom Dryer / Heater / Ventilation Systems (for Japan); Adapters for Airflow Ventilation Systems, Heat Pump Chilled / Hot Water Systems, and Ventilation / Air-Conditioning System Air Resorts (for Japan); Lossnay Central Ventilation Systems (for Japan); Smart Switches for Ventilation Fans and Lossnay (for Japan); IH Cooking Heaters (for Japan); and Rice Cookers (for Japan) allows an attacker within Wi-Fi radio range of an affected product to access the affected product using a hard-coded SSID and password, thereby obtaining device data such as operation status, room set temperature, and room temperature; changing the air-conditioner or Wi-Fi settings; or causing Wi-Fi communication to enter a denial-of-service (DoS) condition.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-17
AI Q&A
2026-06-17
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 10 associated CPEs
Vendor Product Version / Range
mitsubishi_electric room_air_conditioner *
mitsubishi_electric wired_lan_adapter *
mitsubishi_electric refrigerator *
mitsubishi_electric heat_pump_water_heater *
mitsubishi_electric bathroom_dryer *
mitsubishi_electric lossnay_central_ventilation_system *
mitsubishi_electric smart_switch *
mitsubishi_electric ih_cooking_heater *
mitsubishi_electric rice_cooker *
mitsubishi_electric room_air_conditioner 43.00
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Compliance Impact

The vulnerability allows an attacker within Wi-Fi range to access device data such as operation status and temperature settings, change device or Wi-Fi settings, or cause denial-of-service conditions. However, the affected products do not store personal data, so this vulnerability does not directly expose personal information.

Because no personal data is exposed, the vulnerability is less likely to directly impact compliance with data protection regulations such as GDPR or HIPAA, which focus on the protection of personal and sensitive information.

Nevertheless, the ability to tamper with device settings or cause denial-of-service could have indirect effects on operational security and availability, which may be relevant under certain regulatory frameworks depending on the context of use.

Executive Summary

CVE-2026-5667 is a vulnerability in multiple Mitsubishi Electric home appliances caused by the use of hard-coded credentials. This means that certain Wi-Fi-enabled products have a fixed SSID and password embedded in them, which an attacker within Wi-Fi range can use to gain unauthorized access.

Affected products include room air conditioners, wireless LAN adapters, refrigerators, heat pump water heaters, bathroom dryers, ventilation systems, smart switches, IH cooking heaters, and rice cookers, primarily for the Japanese market but also outside Japan.

An attacker exploiting this vulnerability can access device data such as operation status, room set temperature, and room temperature; change air-conditioner or Wi-Fi settings; or cause Wi-Fi communication to enter a denial-of-service (DoS) condition.

The vulnerability specifically affects devices that have never been connected to a router or were reset to factory defaults without proper reconfiguration.

Impact Analysis

If you have an affected Mitsubishi Electric device within Wi-Fi range, an attacker could exploit this vulnerability to:

  • Obtain device data such as operation status, room set temperature, and room temperature.
  • Modify air-conditioner or Wi-Fi settings, potentially disrupting normal operation.
  • Cause Wi-Fi communication to enter a denial-of-service (DoS) state, making the device unavailable over the network.

However, the vulnerability does not expose personal data, as the affected products do not store such information.

To mitigate the risk, users should disable Wi-Fi if not in use or connect the device to a router and update the adapter software to version 43.00 or later.

Detection Guidance

This vulnerability involves the use of hard-coded SSID and password in affected Mitsubishi Electric Wi-Fi-enabled products. Detection involves identifying devices broadcasting or connected using these default credentials within your Wi-Fi range.

You can scan your wireless network for devices broadcasting the known hard-coded SSID or attempt to connect using the known default password to verify if the device is vulnerable.

Specific commands are not provided in the available resources, but general network scanning tools such as 'nmap' or 'iwlist' on Linux can be used to detect Wi-Fi devices and their SSIDs.

  • Use 'iwlist scan' to list available Wi-Fi networks and identify suspicious SSIDs.
  • Use 'nmap' to scan for devices on your network that may correspond to affected products.
  • Attempt to connect to the device using the known hard-coded SSID and password to confirm vulnerability.
Mitigation Strategies

To mitigate this vulnerability, users should either disable Wi-Fi on affected devices if it is not in use or connect the device to a router and update the adapter software to version 43.00 or later.

If the device has never been connected to a router or was reset to factory defaults, ensure proper configuration is performed to avoid exposure to the hard-coded credentials.

Applying available software updates provided by Mitsubishi Electric for affected models is strongly recommended.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-5667. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart