CVE-2025-11774
8.2Mitsubishi Electric · GENESIS64, ICONICS Suite, MobileHMI, MC Works64
A local OS command injection vulnerability in the keypad function of multiple Mitsubishi Electric industrial software products allows local attackers to execute arbitrary executable files.
Executive summary
A local OS command injection vulnerability in Mitsubishi Electric GENESIS64 and related suites could allow a local attacker to execute arbitrary code, leading to total system compromise.
Vulnerability
This vulnerability, identified as CWE-78, exists within the software keyboard (keypad) function. A local attacker with low privileges can tamper with the configuration file for the keypad function, causing the application to execute arbitrary EXE files when a legitimate user interacts with the keypad.
Business impact
The ability to execute arbitrary code locally poses a severe risk to industrial control environments. Successful exploitation allows an attacker to disclose, modify, or delete sensitive information, or cause a denial of service on the host PC. Given the CVSS score of 8.2, this vulnerability is classified as High severity, as it facilitates full system control for an attacker who has already gained local access to the workstation.
Remediation
Immediate Action: Update affected Mitsubishi Electric software to the versions specified in the official vendor advisory (JVNVU97729686) to address the configuration file handling flaw.
Proactive Monitoring: Monitor system logs for the execution of unexpected or unauthorized executable files, particularly those triggered during user interaction with industrial software interfaces.
Compensating Controls: Restrict local file system access to configuration files associated with the keypad function to prevent tampering by unauthorized local users.
Exploitation status
Public Exploit Available: exploit_available (false)
Analyst recommendation
Organizations utilizing affected versions of GENESIS64, ICONICS Suite, MobileHMI, or MC Works64 must prioritize the transition to patched versions provided by Mitsubishi Electric. Given the potential for full system impact and the nature of the vulnerability as an OS command injection, immediate patching is necessary to prevent local privilege escalation and potential disruption of critical operational technology systems.