CVE-2025-11774
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the software keyboard function (hereinafter referred to as "keypad function") of Mitsubishi Electric GENESIS64 versions 10.97.2 CFR3 and prior, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97.2 CFR3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.2 CFR3 and prior, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97.2 CFR3 and prior, Mitsubishi Electric MobileHMI versions 10.97.2 CFR3 and prior, Mitsubishi Electric Iconics Digital Solutions MobileHMI versions 10.97.2 CFR3 and prior, and Mitsubishi Electric MC Works64 all versions allows a local attacker to execute arbitrary executable files (EXE) when a legitimate user uses the keypad function by tampering with the configuration file for the function.
Leer descripción completaMostrar menos
This could allow the attacker to disclose, tamper with, delete, or destroy information stored on the PC where the affected product is installed, or cause a denial-of-service (DoS) condition on the system, through the execution of the EXE.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
- Puntuación base: 8.2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.57%
- Percentil entre todas las CVEs puntuadas: 45
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1203Exploitation for Client Executionexecution85 % - Impacto principal
T1059Command and Scripting Interpreterexecution90 % - Impacto secundario
T1498.002Reflection Amplificationimpact60 % - Impacto secundario
T1565.001Stored Data Manipulationimpact75 %
AV:L + UI:R indica explotación en cliente (T1203: usuario legítimo usa función keypad). OS Command Injection (CWE-78) permite ejecución arbitraria de EXE (T1059). Impactos: ejecución de comandos (primario), DoS (T1498.002 por negación de servicio mencionada), manipulación de datos (T1565.001 por alt
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (4)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-78
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-11774",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-11774",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-12-19T19:08:06.554691Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 8.2,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 1.5
}
]
},
"affected": [
{
"source": "Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp",
"affectedData": [
{
"vendor": "Mitsubishi Electric Corporation",
"product": "GENESIS64",
"versions": [
{
"status": "affected",
"version": "Version 10.97.2 CFR3 and prior"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Mitsubishi Electric Iconics Digital Solutions",
"product": "GENESIS64",
"versions": [
{
"status": "affected",
"version": "Version 10.97.2 CFR3 and prior"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Mitsubishi Electric Corporation",
"product": "ICONICS Suite",
"versions": [
{
"status": "affected",
"version": "Version 10.97.2 CFR3 and prior"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Mitsubishi Electric Iconics Digital Solutions",
"product": "ICONICS Suite",
"versions": [
{
"status": "affected",
"version": "Version 10.97.2 CFR3 and prior"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Mitsubishi Electric Corporation",
"product": "MobileHMI",
"versions": [
{
"status": "affected",
"version": "Version 10.97.2 CFR3 and prior"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Mitsubishi Electric Iconics Digital Solutions",
"product": "MobileHMI",
"versions": [
{
"status": "affected",
"version": "Version 10.97.2 CFR3 and prior"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Mitsubishi Electric Corporation",
"product": "MC Works64",
"versions": [
{
"status": "affected",
"version": "All versions"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-12-19T01:16:04.570",
"references": [
{
"url": "https://jvn.jp/vu/JVNVU97729686/",
"source": "Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp"
},
{
"url": "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-018_en.pdf",
"source": "Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the software keyboard function (hereinafter referred to as \"keypad function\") of Mitsubishi Electric GENESIS64 versions 10.97.2 CFR3 and prior, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97.2 CFR3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.2 CFR3 and prior, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97.2 CFR3 and prior, Mitsubishi Electric MobileHMI versions 10.97.2 CFR3 and prior, Mitsubishi Electric Iconics Digital Solutions MobileHMI versions 10.97.2 CFR3 and prior, and Mitsubishi Electric MC Works64 all versions allows a local attacker to execute arbitrary executable files (EXE) when a legitimate user uses the keypad function by tampering with the configuration file for the function. This could allow the attacker to disclose, tamper with, delete, or destroy information stored on the PC where the affected product is installed, or cause a denial-of-service (DoS) condition on the system, through the execution of the EXE."
},
{
"lang": "es",
"value": "Vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando del sistema operativo ('OS Command Injection') en la función de teclado de software (en adelante, denominada 'función de teclado numérico') de Mitsubishi Electric GENESIS64 versiones 10.97.2 CFR3 y anteriores, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versiones 10.97.2 CFR3 y anteriores, Mitsubishi Electric ICONICS Suite versiones 10.97.2 CFR3 y anteriores, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versiones 10.97.2 CFR3 y anteriores, Mitsubishi Electric MobileHMI versiones 10.97.2 CFR3 y anteriores, Mitsubishi Electric Iconics Digital Solutions MobileHMI versiones 10.97.2 CFR3 y anteriores, y Mitsubishi Electric MC Works64 todas las versiones permite a un atacante local ejecutar archivos ejecutables arbitrarios (EXE) cuando un usuario legítimo utiliza la función de teclado numérico manipulando el archivo de configuración de la función. Esto podría permitir al atacante divulgar, manipular, eliminar o destruir información almacenada en el PC donde está instalado el producto afectado, o causar una condición de denegación de servicio (DoS) en el sistema, mediante la ejecución del EXE."
}
],
"lastModified": "2026-09-30T20:10:00.247",
"sourceIdentifier": "Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp"
}