PT-2026-50362 · Mitsubishi · Heat Pump Water Heaters+15

CVE-2026-5667

·

Published

2026-06-17

·

Updated

2026-06-19

CVSS v4.0

7.2

High

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Mitsubishi Electric Room Air Conditioners (affected versions not specified) Mitsubishi Electric Wireless LAN Adapters for Room Air Conditioners (affected versions not specified) Mitsubishi Electric Wireless LAN Adapters for Packaged Air Conditioners (affected versions not specified) Mitsubishi Electric Refrigerators (affected versions not specified) Mitsubishi Electric Heat Pump Water Heaters / HEMS-Compatible Adapters / Wireless LAN Adapters (affected versions not specified) Mitsubishi Electric Bathroom Dryer / Heater / Ventilation Systems (affected versions not specified) Mitsubishi Electric Adapters for Airflow Ventilation Systems, Heat Pump Chilled / Hot Water Systems, and Ventilation / Air-Conditioning System Air Resorts (affected versions not specified) Mitsubishi Electric Lossnay Central Ventilation Systems (affected versions not specified) Mitsubishi Electric Smart Switches for Ventilation Fans and Lossnay (affected versions not specified) Mitsubishi Electric IH Cooking Heaters (affected versions not specified) Mitsubishi Electric Rice Cookers (affected versions not specified) Mitsubishi MAC-577IF-2E WiFi Adapters (affected versions not specified)
Description The use of hard-coded credentials allows an attacker within Wi-Fi radio range to access affected products using a hard-coded SSID and password. This access enables the attacker to obtain device data, such as operation status, room set temperature, and room temperature, change air-conditioner or Wi-Fi settings, or cause a denial-of-service (DoS) condition, which is a state where the device becomes unavailable to legitimate users. Additionally, unauthenticated remote control is possible via probe request reconnaissance.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5667

Affected Products

Adapters For Airflow Ventilation Systems
Bathroom Dryer / Heater / Ventilation Systems
Hems-Compatible Adapters
Heat Pump Chilled / Hot Water Systems
Heat Pump Water Heaters
Ih Cooking Heaters
Lossnay Central Ventilation Systems
Mac-577If-2E Wifi Adapters
Refrigerators
Rice Cookers
Room Air Conditioners
Smart Switches For Ventilation Fans/Lossnay
Ventilation / Air-Conditioning System Air Resorts
Wireless Lan Adapters
Wireless Lan Adapters For Packaged Air Conditioners
Wireless Lan Adapters For Room Air Conditioners