Vulnerability record · CVE-2019-14931 · published 28 October 2019
CVE-2019-14931: Mitsubishi Electric and INEA ME-RTU unauthenticated OS command injection
Mitsubishielectric · Smartrtu Firmware
ME-RTU devices from Mitsubishi Electric Europe (through 2.02) and INEA (through 3.0) pass unsanitised user input from the Mobile Connection Test to the system shell. A shell command separator in the host variable lets an unauthenticated remote attacker run arbitrary OS commands on the RTU. Because these are industrial remote terminal units, successful exploitation gives full control of a field device.
Description
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote OS Command Injection vulnerability allows an attacker to execute arbitrary commands on the RTU due to the passing of unsafe user supplied data to the RTU's system shell. Functionality in mobile.php provides users with the ability to ping sites or IP addresses via Mobile Connection Test. When the Mobile Connection Test is submitted, action.php is called to execute the test. An attacker can use a shell command separator (;) in the host variable to execute operating system commands upon submitting the test data.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote command execution on an internet- or network-exposed industrial RTU with a CVSS score of 9.8 and high EPSS probability.
What it is
ME-RTU devices from Mitsubishi Electric Europe (through 2.02) and INEA (through 3.0) pass unsanitised user input from the Mobile Connection Test to the system shell. A shell command separator in the host variable lets an unauthenticated remote attacker run arbitrary OS commands on the RTU. Because these are industrial remote terminal units, successful exploitation gives full control of a field device.
Impact
An attacker gains arbitrary command execution on the RTU with the privileges of the web service, allowing data theft, configuration changes, disruption of the device, and use of the RTU as a pivot into the operational network.
Attack surface
Reachable over the network through the web interface: mobile.php exposes the Mobile Connection Test, which submits to action.php. No authentication and no user interaction are required, matching the CVSS vector AV:N/AC:L/PR:N/UI:N.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.5809, 99th percentile) and public references are tagged Exploit, indicating proof-of-concept code is publicly available. No ransomware association is documented.
What to do
- Apply the vendor firmware update for ME-RTU (Mitsubishi Electric Europe and INEA) as soon as it is available; the record does not state a fixed version, so confirm with the vendor.
- If patching is not possible, remove the RTU web interface from untrusted networks and restrict access to a management VLAN or VPN with strict allowlists.
- Disable or block the Mobile Connection Test functionality if it is not operationally required.
- Place the RTU behind a firewall or reverse proxy that filters requests to mobile.php and action.php and rejects shell metacharacters in the host parameter.
- Change default credentials and audit accounts, even though this flaw is unauthenticated, to limit follow-on access.
Detection
- Monitor RTU and web server logs for requests to mobile.php and action.php containing shell metacharacters such as ;, |, &&, or backticks in the host parameter.
- Alert on unexpected child processes spawned by the RTU web service (for example shell, ping, or netcat) and on outbound connections from the RTU to unfamiliar hosts.
- Baseline normal RTU traffic and flag anomalous outbound traffic or interactive sessions originating from the device.
- Review device configuration and file integrity for unauthorised changes that would indicate post-exploitation activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.mogozobo.com/ | Third Party Advisory |
| https://www.mogozobo.com/?p=3593 | ExploitThird Party Advisory |
| https://www.mogozobo.com/ | Third Party Advisory |
| https://www.mogozobo.com/?p=3593 | ExploitThird Party Advisory |
Track CVE-2019-14931 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-14931), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.