CVE-2019-14931
Description
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote OS Command Injection vulnerability allows an attacker to execute arbitrary commands on the RTU due to the passing of unsafe user supplied data to the RTU's system shell. Functionality in mobile.php provides users with the ability to ping sites or IP addresses via Mobile Connection Test. When the Mobile Connection Test is submitted, action.php is called to execute the test. An attacker can use a shell command separator (;) in the host variable to execute operating system commands upon submitting the test data.
In plain language
AI Act nowCVE-2019-14931 is a serious flaw in certain Mitsubishi Electric ME-RTU devices that lets an attacker run commands over the network without logging in; if you use these units and they’re reachable, you should treat it as urgent—there’s no known patch version provided.
CVE-2019-14931 is an unauthenticated remote OS Command Injection in Mitsubishi Electric ME-RTU “Mobile Connection Test” handling (mobile.php calls backend action.php), where an attacker can manipulate the `host` input (e.g., using shell separators like `;`) to execute arbitrary commands on the device.
What to do now
- Check whether you run Mitsubishi Electric ME-RTU devices (“smartrtu firmware” and “me-rtu firmware”) and identify whether they are on versions through 2.02 (ME-RTU) or through 3.0 (INEA ME-RTU).
- Verify whether the “Mobile Connection Test” feature is reachable from the network, and whether the related endpoints (mobile.php / action.php) are exposed (directly or indirectly) from anywhere outside your trusted network.
- If the device is reachable, immediately isolate it from the internet and untrusted networks (firewall/VPN segmentation) so attackers can’t reach the vulnerable feature.
- Contact Mitsubishi Electric support or your integrator and ask for a confirmed fixed firmware version for CVE-2019-14931, since no patch information is available in the provided advisories.
- Create an incident response plan for ME-RTU compromise: preserve logs/config, review for unexpected outbound connections or system command activity, and prepare to restore known-good configuration if tampering is found.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Ботнет Evooo1Bot превращает зараженные устройства в проксиru-ru·Хакер (xakep.ru)· Exploited Alcatel ddos-botnet
- Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoSen·Dark Reading· Exploited Alcatel ddos-botnet
- Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxiesen·The Hacker News· Exploited Alcatel OmniPCX Enterprise ddos-botnet
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2019-14931 and every CVE in our database. Create a free account — no credit card required.
Create Free Account