← Vulnerability feed

Vulnerability record · CVE-2019-14931 · published 28 October 2019

CVE-2019-14931: Mitsubishi Electric and INEA ME-RTU unauthenticated OS command injection

Mitsubishielectric · Smartrtu Firmware

ME-RTU devices from Mitsubishi Electric Europe (through 2.02) and INEA (through 3.0) pass unsanitised user input from the Mobile Connection Test to the system shell. A shell command separator in the host variable lets an unauthenticated remote attacker run arbitrary OS commands on the RTU. Because these are industrial remote terminal units, successful exploitation gives full control of a field device.

9.8 CVSS 3.1 Critical EPSS 58% · top 0.9% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 10.0
58%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote OS Command Injection vulnerability allows an attacker to execute arbitrary commands on the RTU due to the passing of unsafe user supplied data to the RTU's system shell. Functionality in mobile.php provides users with the ability to ping sites or IP addresses via Mobile Connection Test. When the Mobile Connection Test is submitted, action.php is called to execute the test. An attacker can use a shell command separator (;) in the host variable to execute operating system commands upon submitting the test data.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityUnauthenticated remote command execution on an internet- or network-exposed industrial RTU with a CVSS score of 9.8 and high EPSS probability.

What it is

ME-RTU devices from Mitsubishi Electric Europe (through 2.02) and INEA (through 3.0) pass unsanitised user input from the Mobile Connection Test to the system shell. A shell command separator in the host variable lets an unauthenticated remote attacker run arbitrary OS commands on the RTU. Because these are industrial remote terminal units, successful exploitation gives full control of a field device.

Impact

An attacker gains arbitrary command execution on the RTU with the privileges of the web service, allowing data theft, configuration changes, disruption of the device, and use of the RTU as a pivot into the operational network.

Attack surface

Reachable over the network through the web interface: mobile.php exposes the Mobile Connection Test, which submits to action.php. No authentication and no user interaction are required, matching the CVSS vector AV:N/AC:L/PR:N/UI:N.

Exploitation

Not listed in CISA KEV, but EPSS is high (0.5809, 99th percentile) and public references are tagged Exploit, indicating proof-of-concept code is publicly available. No ransomware association is documented.

What to do

  • Apply the vendor firmware update for ME-RTU (Mitsubishi Electric Europe and INEA) as soon as it is available; the record does not state a fixed version, so confirm with the vendor.
  • If patching is not possible, remove the RTU web interface from untrusted networks and restrict access to a management VLAN or VPN with strict allowlists.
  • Disable or block the Mobile Connection Test functionality if it is not operationally required.
  • Place the RTU behind a firewall or reverse proxy that filters requests to mobile.php and action.php and rejects shell metacharacters in the host parameter.
  • Change default credentials and audit accounts, even though this flaw is unauthenticated, to limit follow-on access.

Detection

  • Monitor RTU and web server logs for requests to mobile.php and action.php containing shell metacharacters such as ;, |, &&, or backticks in the host parameter.
  • Alert on unexpected child processes spawned by the RTU web service (for example shell, ping, or netcat) and on outbound connections from the RTU to unfamiliar hosts.
  • Baseline normal RTU traffic and flag anomalous outbound traffic or interactive sessions originating from the device.
  • Review device configuration and file integrity for unauthorised changes that would indicate post-exploitation activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.mogozobo.com/ Third Party Advisory
https://www.mogozobo.com/?p=3593 ExploitThird Party Advisory
https://www.mogozobo.com/ Third Party Advisory
https://www.mogozobo.com/?p=3593 ExploitThird Party Advisory

Track CVE-2019-14931 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-14926Mitsubishielectric smartrtu firmware hard-coded credentials vulnerabilityAn issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Hard-coded SSH keys allow…EPSS 2.1%9.8CVE-2019-14929Mitsubishielectric smartrtu firmware insufficiently protected credentials vulnerabilityAn issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Stored cleartext password…EPSS 1.9%9.8CVE-2019-14930Mitsubishielectric smartrtu firmware hard-coded credentials vulnerabilityAn issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Undocumented hard-coded u…EPSS 2.3%7.5CVE-2018-16060Mitsubishielectric smartrtu firmware vulnerabilityMitsubishi Electric Europe B.V. SmartRTU devices allow remote attackers to obtain sensitive information (directory listing and source code) via a dir…EPSS 20%7.5CVE-2019-14927Mitsubishielectric smartrtu firmware missing authentication for critical function vulnerabilityAn issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote…EPSS 42%6.5CVE-2019-14925Mitsubishielectric smartrtu firmware incorrect default permissions vulnerabilityAn issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A world-readable /usr/sma…EPSS 1.3%6.1CVE-2018-16061Mitsubishielectric smartrtu firmware cross-site scripting vulnerabilityMitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php.EPSS 4.0%5.4CVE-2019-14928Mitsubishielectric smartrtu firmware cross-site scripting vulnerabilityAn issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A number of stored cross-…EPSS 44%

Source: NIST National Vulnerability Database (record CVE-2019-14931), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.