CVE-2025-5023
7.1Mitsubishi Electric · EcoGuideTAB (PV-DR004J, PV-DR004JA)
Mitsubishi Electric EcoGuideTAB photovoltaic monitors contain a hard-coded credential vulnerability allowing attackers within Wi-Fi range to access, tamper with, or disrupt device operations.
Executive summary
Mitsubishi Electric EcoGuideTAB photovoltaic monitoring systems contain a hard-coded credential vulnerability that allows unauthorized local attackers to compromise system integrity and availability.
Vulnerability
This vulnerability involves the use of hard-coded credentials within the communication link between the measurement and display units, which an unauthenticated attacker within physical Wi-Fi range can exploit to gain unauthorized access.
Business impact
Successful exploitation allows an attacker to disclose sensitive energy production data, modify system configurations, or trigger a denial-of-service condition. Given the CVSS score of 7.1, this represents a significant risk to the operational availability and data integrity of the photovoltaic monitoring infrastructure.
Remediation
Immediate Action: Review the vendor advisory at the provided JVN reference for guidance, noting that these products were discontinued in 2015 and have reached end-of-support status.
Proactive Monitoring: Implement network segmentation to isolate the Wi-Fi communication between the measurement and display units, and monitor for unauthorized attempts to connect to these specific device segments.
Compensating Controls: Given the lack of a patch, restrict physical access to the Wi-Fi broadcast range of the devices and disable wireless communication interfaces if they are not strictly required for operation.
Exploitation status
Public Exploit Available: No confirmed public exploit available.
Analyst recommendation
Due to the end-of-life status of the affected hardware, official patches are unlikely to be provided. Organizations utilizing these devices should prioritize decommissioning or replacing the hardware, as the hard-coded credentials cannot be remediated through standard software updates. If immediate replacement is not feasible, strict physical and logical access controls must be enforced to mitigate the risk of unauthorized local exploitation.