Mitsubishi Electric
PV-DR004J
Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Corporation photovoltaic system monitor “EcoGuideTAB” PV-DR004J all versions and PV...
2025-07-11
Description
Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Corporation photovoltaic system monitor “EcoGuideTAB” PV-DR004J all versions and PV-DR004JA all versions allows an attacker within the Wi-Fi communication range between the units of the product (measurement unit and display unit) to disclose information such as generated power and electricity sold back to the grid stored in the product, tamper with or destroy stored or configured information in the product, or cause a Denial-of-Service (DoS) condition on the product, by using hardcoded user ID and password common to the product series obtained by exploiting CVE-2025-5022
AI Analyst Comment
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Description Summary:
A privilege escalation and remote code execution vulnerability exists in ZipGenius v6.3.2.3116 and earlier due to an issue within the zipgenius.exe binary.
Executive Summary:
A critical privilege escalation and arbitrary code execution flaw in ZipGenius allows remote attackers to execute code with elevated permissions via malicious archives.
Vulnerability Details
CVE-ID: CVE-2025-50330
Affected Software: ZipGenius Team ZipGenius
Affected Versions: ZipGenius v6.3.2.3116 and before
Vulnerability: This is a privilege escalation and arbitrary code execution vulnerability triggered through the zipgenius.exe binary. An unauthenticated remote attacker can exploit this by delivering a crafted archive to a user or by triggering the vulnerable path during standard file processing workflows.
Business Impact
The exploitation of this vulnerability poses a severe risk to organizational security, as it allows an attacker to execute arbitrary code with elevated privileges on the host system. Given the CVSS score of 8.8, this vulnerability is classified as high severity, potentially leading to full system compromise, data theft, and unauthorized lateral movement within the network.
Remediation Plan
Immediate Action: Users should restrict the use of ZipGenius until an official patch is released by the vendor. Monitor the vendor advisory URL for the release of a version that addresses this vulnerability.
Proactive Monitoring: Security teams should monitor endpoint logs for suspicious execution patterns originating from zipgenius.exe, particularly when interacting with untrusted or externally sourced archive files.
Compensating Controls: Deploy endpoint protection solutions to detect and block the execution of unauthorized processes spawned by archive utilities. Ensure that users are instructed not to open archive files from untrusted or unknown sources.
Exploitation Status
Public Exploit Available: No (no confirmed public exploit available).
Analyst Notes: As of July 21, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently dangerous due to its ability to facilitate remote code execution via common user interactions.
Analyst Recommendation
Given the potential for complete system compromise, organizations should treat this vulnerability with extreme urgency. Immediately implement restrictions on the use of the affected software and ensure that security monitoring tools are configured to alert on anomalous activity linked to the application.