AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-14931

CRITICAL · CVSS 9.8 EPSS 57.66%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-10-28 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. Its EPSS score suggests a 57.7% probability of exploitation in the next 30 days. It may be remotely exploitable.

CVE
CVE-2019-14931
Severity
CRITICAL
CVSS
9.8
EPSS
57.66%

Original NVD Description

An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote OS Command Injection vulnerability allows an attacker to execute arbitrary commands on the RTU due to the passing of unsafe user supplied data to the RTU's system shell. Functionality in mobile.php provides users with the ability to ping sites or IP addresses via Mobile Connection Test. When the Mobile Connection Test is submitted, action.php is called to execute the test. An attacker can use a shell command separator (;) in the host variable to execute operating system commands upon submitting the test data.

Related CVEs

Other vulnerabilities affecting the same vendor(s)