Missing Authentication Vulnerability in Mitsubishi Electric Air Conditioning Products
CVE-2025-3699
Key Information:
- Vendor
- CVE Published:
- 26 June 2025
What is CVE-2025-3699?
A missing authentication vulnerability exists in various Mitsubishi Electric air conditioning products, allowing a remote, unauthenticated attacker to bypass critical authentication mechanisms. This flaw enables unauthorized control over the air conditioning systems as well as the potential to access and disclose sensitive information. Furthermore, attackers can exploit this vulnerability to manipulate firmware components of the affected systems, posing significant security risks and operational disruptions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
AE-200A All versions
AE-200E All versions
AE-200J All versions
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
