CVE Tools

CVE-2019-14931

Exploitation likely. EPSS gives it a 58% chance of exploitation in the next 30 days. No fix published yet.

Published Updated Sources: CVE.org, NVD, CSAF

What to do

No fixed build or workaround is published yet. Limit exposure and watch for a patch.

Steps

Written by AI from the record
  1. Check whether you run Mitsubishi Electric ME-RTU devices (“smartrtu firmware” and “me-rtu firmware”) and identify whether they are on versions through 2.02 (ME-RTU) or through 3.0 (INEA ME-RTU).
  2. Verify whether the “Mobile Connection Test” feature is reachable from the network, and whether the related endpoints (mobile.php / action.php) are exposed (directly or indirectly) from anywhere outside your trusted network.
  3. If the device is reachable, immediately isolate it from the internet and untrusted networks (firewall/VPN segmentation) so attackers can’t reach the vulnerable feature.
  4. Contact Mitsubishi Electric support or your integrator and ask for a confirmed fixed firmware version for CVE-2019-14931, since no patch information is available in the provided advisories.
  5. Create an incident response plan for ME-RTU compromise: preserve logs/config, review for unexpected outbound connections or system command activity, and prepare to restore known-good configuration if tampering is found.

What it is

From the CVE record

An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote OS Command Injection vulnerability allows an attacker to execute arbitrary commands on the RTU due to the passing of unsafe user supplied data to the RTU's system shell. Functionality in mobile.php provides users with the ability to ping sites or IP addresses via Mobile Connection Test. When the Mobile Connection Test is submitted, action.php is called to execute the test. An attacker can use a shell command separator (;) in the host variable to execute operating system commands upon submitting the test data.

In plain language

Written by AI from the record

CVE-2019-14931 is a serious flaw in certain Mitsubishi Electric ME-RTU devices that lets an attacker run commands over the network without logging in; if you use these units and they’re reachable, you should treat it as urgent—there’s no known patch version provided.

CVE-2019-14931 is an unauthenticated remote OS Command Injection in Mitsubishi Electric ME-RTU “Mobile Connection Test” handling (mobile.php calls backend action.php), where an attacker can manipulate the `host` input (e.g., using shell separators like `;`) to execute arbitrary commands on the device.

If you're affected

  • Full device takeover
  • Sensitive device data theft
  • Configuration tampering
  • Operational disruption

Exploitation

Where each signal puts this CVE on the scale from published to confirmed exploited.

EPSS99th
CISA KEV

Not in the catalog. CISA has not confirmed exploitation.

Public exploits

No public exploit or proof of concept found in the sources we track.

EPSS

58% chance of exploitation activity in the next 30 days, which ranks it in the 99th percentile of scored CVEs.

Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.

Lifecycle

5 events over 2432 days, from the signal feeds we watch.

  1. OpenVAS check added
  2. Record updated
  3. Publishedweakness classified, att&ck mapped

Affected products

And 1 more affected product. See all after sign-in

Technical detail

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Scored 9.8 by NVD.

How it is reached

  • Attack Vector NetworkExploitable remotely over the network without any special conditions
  • Attack Complexity LowNo special conditions — the attack can be reliably reproduced
  • Privileges Required NoneNo authentication required — anyone can exploit this
  • User Interaction NoneNo user interaction needed — fully automated exploitation

Scope

  • Scope UnchangedImpact is limited to the vulnerable component itself

Impact if exploited

  • Confidentiality HighTotal information disclosure — all data in the component is compromised
  • Integrity HighTotal loss of integrity — attacker can modify any data in the component
  • Availability HighTotal denial of service — the component is completely unavailable

Weaknesses

ATT&CK techniques

Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.

Sources

Watch the software you run.

My Stack ranks new CVEs for your products by real-world exploitation, so the next serious one reaches you without reading every advisory.

We'll flag the next CVE, public exploit or patch for Smartrtu Firmware, not every advisory.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store