Description
Cross-site scripting vulnerability in Mitsubishi Electric consumer electronics products (Air Conditioning, Wi-Fi Interface, Refrigerator, HEMS adapter, Remote control with Wi-Fi Interface, BATHROOM THERMO VENTILATOR, Rice cooker, Mitsubishi Electric HEMS control adapter, Energy Recovery Ventilator, Smart Switch and Air Purifier) allows a remote unauthenticated attacker to execute an malicious script on a user's browser to disclose information, etc. The wide range of models/versions of Mitsubishi Electric consumer electronics products are affected by this vulnerability. As for the affected product models/versions, see the Mitsubishi Electric's advisory which is listed in [References] section.

Published: 2022-11-08
Score: 6.1 Medium
EPSS: 1.5% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-36365 Cross-site scripting vulnerability in Mitsubishi Electric consumer electronics products (Air Conditioning, Wi-Fi Interface, Refrigerator, HEMS adapter, Remote control with Wi-Fi Interface, BATHROOM THERMO VENTILATOR, Rice cooker, Mitsubishi Electric HEMS control adapter, Energy Recovery Ventilator, Smart Switch and Air Purifier) allows a remote unauthenticated attacker to execute an malicious script on a user's browser to disclose information, etc. The wide range of models/versions of Mitsubishi Electric consumer electronics products are affected by this vulnerability. As for the affected product models/versions, see the Mitsubishi Electric's advisory which is listed in [References] section.
History

Thu, 01 May 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Mitsubishielectric Ma-ew85s-e Ma-ew85s-e Firmware Ma-ew85s-uk Ma-ew85s-uk Firmware Mac-507if-e Mac-507if-e Firmware Mac-587if-e Mac-587if-e Firmware Mac-587if2-e Mac-587if2-e Firmware Mac-588if-e Mac-588if-e Firmware Mfz-gxt50\/60\/73vfk Mfz-gxt50\/60\/73vfk Firmware Mfz-xt50\/60vfk Mfz-xt50\/60vfk Firmware Msxy-fp05\/07\/10\/13\/18\/20\/24vgk-sg1 Msxy-fp05\/07\/10\/13\/18\/20\/24vgk-sg1 Firmware Msy-gp10\/13\/15\/18\/20\/24vfk-sg1 Msy-gp10\/13\/15\/18\/20\/24vfk-sg1 Firmware Msz-ap15\/20\/25\/35\/42\/50\/60\/71vgk-e2 Msz-ap15\/20\/25\/35\/42\/50\/60\/71vgk-e2 Firmware Msz-ap15\/20\/25\/35\/42\/50\/60\/71vgk-er2 Msz-ap15\/20\/25\/35\/42\/50\/60\/71vgk-er2 Firmware Msz-ap15\/20\/25\/35\/42\/50\/60\/71vgk-et2 Msz-ap15\/20\/25\/35\/42\/50\/60\/71vgk-et2 Firmware Msz-ap22\/25\/35\/42\/50\/60\/71\/80vgkd-a2 Msz-ap22\/25\/35\/42\/50\/60\/71\/80vgkd-a2 Firmware Msz-ap22\/25\/35\/42\/50\/61\/70\/80vgkd-a1 Msz-ap22\/25\/35\/42\/50\/61\/70\/80vgkd-a1 Firmware Msz-ap25\/35\/42\/50\/60\/71vgk-e3 Msz-ap25\/35\/42\/50\/60\/71vgk-e3 Firmware Msz-ap25\/35\/42\/50\/60\/71vgk-er3 Msz-ap25\/35\/42\/50\/60\/71vgk-er3 Firmware Msz-ap25\/35\/42\/50\/60\/71vgk-et3 Msz-ap25\/35\/42\/50\/60\/71vgk-et3 Firmware Msz-ap25\/35\/42\/50vgk-e1 Msz-ap25\/35\/42\/50vgk-e1 Firmware Msz-ap25\/35\/42\/50vgk-e7 Msz-ap25\/35\/42\/50vgk-e7 Firmware Msz-ap25\/35\/42\/50vgk-e8 Msz-ap25\/35\/42\/50vgk-e8 Firmware Msz-ap25\/35\/42\/50vgk-en1 Msz-ap25\/35\/42\/50vgk-en1 Firmware Msz-ap25\/35\/42\/50vgk-en2 Msz-ap25\/35\/42\/50vgk-en2 Firmware Msz-ap25\/35\/42\/50vgk-en3 Msz-ap25\/35\/42\/50vgk-en3 Firmware Msz-ap25\/35\/42\/50vgk-er1 Msz-ap25\/35\/42\/50vgk-er1 Firmware Msz-ap25\/35\/42\/50vgk-et1 Msz-ap25\/35\/42\/50vgk-et1 Firmware Msz-ay25\/35\/42\/50vgk-e1 Msz-ay25\/35\/42\/50vgk-e1 Firmware Msz-ay25\/35\/42\/50vgk-e6 Msz-ay25\/35\/42\/50vgk-e6 Firmware Msz-ay25\/35\/42\/50vgk-er1 Msz-ay25\/35\/42\/50vgk-er1 Firmware Msz-ay25\/35\/42\/50vgk-et1 Msz-ay25\/35\/42\/50vgk-et1 Firmware Msz-ay25\/35\/42\/50vgk-sc1 Msz-ay25\/35\/42\/50vgk-sc1 Firmware Msz-ay25\/35\/42\/50vgkp-e6 Msz-ay25\/35\/42\/50vgkp-e6 Firmware Msz-ay25\/35\/42\/50vgkp-er1 Msz-ay25\/35\/42\/50vgkp-er1 Firmware Msz-ay25\/35\/42\/50vgkp-et1 Msz-ay25\/35\/42\/50vgkp-et1 Firmware Msz-ay25\/35\/42\/50vgkp-sc1 Msz-ay25\/35\/42\/50vgkp-sc1 Firmware Msz-bt20\/25\/35\/50vgk-e1 Msz-bt20\/25\/35\/50vgk-e1 Firmware Msz-bt20\/25\/35\/50vgk-e2 Msz-bt20\/25\/35\/50vgk-e2 Firmware Msz-bt20\/25\/35\/50vgk-e3 Msz-bt20\/25\/35\/50vgk-e3 Firmware Msz-bt20\/25\/35\/50vgk-er1 Msz-bt20\/25\/35\/50vgk-er1 Firmware Msz-bt20\/25\/35\/50vgk-er2 Msz-bt20\/25\/35\/50vgk-er2 Firmware Msz-bt20\/25\/35\/50vgk-et1 Msz-bt20\/25\/35\/50vgk-et1 Firmware Msz-bt20\/25\/35\/50vgk-et2 Msz-bt20\/25\/35\/50vgk-et2 Firmware Msz-bt20\/25\/35\/50vgk-et3 Msz-bt20\/25\/35\/50vgk-et3 Firmware Msz-ef18\/22\/25\/35\/42\/50vgkb-e1 Msz-ef18\/22\/25\/35\/42\/50vgkb-e1 Firmware Msz-ef18\/22\/25\/35\/42\/50vgkb-e2 Msz-ef18\/22\/25\/35\/42\/50vgkb-e2 Firmware Msz-ef18\/22\/25\/35\/42\/50vgks-e1 Msz-ef18\/22\/25\/35\/42\/50vgks-e1 Firmware Msz-ef18\/22\/25\/35\/42\/50vgks-e2 Msz-ef18\/22\/25\/35\/42\/50vgks-e2 Firmware Msz-ef18\/22\/25\/35\/42\/50vgkw-e1 Msz-ef18\/22\/25\/35\/42\/50vgkw-e1 Firmware Msz-ef18\/22\/25\/35\/42\/50vgkw-e2 Msz-ef18\/22\/25\/35\/42\/50vgkw-e2 Firmware Msz-ef22\/25\/35\/42\/50vgkb-a1 Msz-ef22\/25\/35\/42\/50vgkb-a1 Firmware Msz-ef22\/25\/35\/42\/50vgkb-er1 Msz-ef22\/25\/35\/42\/50vgkb-er1 Firmware Msz-ef22\/25\/35\/42\/50vgkb-er2 Msz-ef22\/25\/35\/42\/50vgkb-er2 Firmware Msz-ef22\/25\/35\/42\/50vgkb-et1 Msz-ef22\/25\/35\/42\/50vgkb-et1 Firmware Msz-ef22\/25\/35\/42\/50vgkb-et2 Msz-ef22\/25\/35\/42\/50vgkb-et2 Firmware Msz-ef22\/25\/35\/42\/50vgks-a1 Msz-ef22\/25\/35\/42\/50vgks-a1 Firmware Msz-ef22\/25\/35\/42\/50vgks-er1 Msz-ef22\/25\/35\/42\/50vgks-er1 Firmware Msz-ef22\/25\/35\/42\/50vgks-er2 Msz-ef22\/25\/35\/42\/50vgks-er2 Firmware Msz-ef22\/25\/35\/42\/50vgks-et1 Msz-ef22\/25\/35\/42\/50vgks-et1 Firmware Msz-ef22\/25\/35\/42\/50vgks-et2 Msz-ef22\/25\/35\/42\/50vgks-et2 Firmware Msz-ef22\/25\/35\/42\/50vgkw-a1 Msz-ef22\/25\/35\/42\/50vgkw-a1 Firmware Msz-ef22\/25\/35\/42\/50vgkw-er1 Msz-ef22\/25\/35\/42\/50vgkw-er1 Firmware Msz-ef22\/25\/35\/42\/50vgkw-er2 Msz-ef22\/25\/35\/42\/50vgkw-er2 Firmware Msz-ef22\/25\/35\/42\/50vgkw-et1 Msz-ef22\/25\/35\/42\/50vgkw-et1 Firmware Msz-ef22\/25\/35\/42\/50vgkw-et2 Msz-ef22\/25\/35\/42\/50vgkw-et2 Firmware Msz-exa09\/12vak Msz-exa09\/12vak Firmware Msz-eza09\/12vak Msz-eza09\/12vak Firmware Msz-ft25\/35\/50vgk-e1 Msz-ft25\/35\/50vgk-e1 Firmware Msz-ft25\/35\/50vgk-e2 Msz-ft25\/35\/50vgk-e2 Firmware Msz-ft25\/35\/50vgk-et1 Msz-ft25\/35\/50vgk-et1 Firmware Msz-ft25\/35\/50vgk-sc1 Msz-ft25\/35\/50vgk-sc1 Firmware Msz-ft25\/35\/50vgk-sc2 Msz-ft25\/35\/50vgk-sc2 Firmware Msz-gzy09\/12\/18vfk Msz-gzy09\/12\/18vfk Firmware Msz-hr25\/35\/42\/50\/60\/71vfk-e1 Msz-hr25\/35\/42\/50\/60\/71vfk-e1 Firmware Msz-hr25\/35\/42\/50\/60\/71vfk-er1 Msz-hr25\/35\/42\/50\/60\/71vfk-er1 Firmware Msz-hr25\/35\/42\/50\/60\/71vfk-et1 Msz-hr25\/35\/42\/50\/60\/71vfk-et1 Firmware Msz-hr25\/35\/42\/50vfk-e6 Msz-hr25\/35\/42\/50vfk-e6 Firmware Msz-ky09\/12\/18vfk Msz-ky09\/12\/18vfk Firmware Msz-ln18\/25\/35\/50\/60vg2b-e2 Msz-ln18\/25\/35\/50\/60vg2b-e2 Firmware Msz-ln18\/25\/35\/50\/60vg2b-e3 Msz-ln18\/25\/35\/50\/60vg2b-e3 Firmware Msz-ln18\/25\/35\/50\/60vg2r-e2 Msz-ln18\/25\/35\/50\/60vg2r-e2 Firmware Msz-ln18\/25\/35\/50\/60vg2r-e3 Msz-ln18\/25\/35\/50\/60vg2r-e3 Firmware Msz-ln18\/25\/35\/50\/60vg2v-e2 Msz-ln18\/25\/35\/50\/60vg2v-e2 Firmware Msz-ln18\/25\/35\/50\/60vg2v-e3 Msz-ln18\/25\/35\/50\/60vg2v-e3 Firmware Msz-ln18\/25\/35\/50\/60vg2w-e2 Msz-ln18\/25\/35\/50\/60vg2w-e2 Firmware Msz-ln18\/25\/35\/50\/60vg2w-e3 Msz-ln18\/25\/35\/50\/60vg2w-e3 Firmware Msz-ln18\/25\/35\/50\/60vg2w-er2 Msz-ln18\/25\/35\/50\/60vg2w-er2 Firmware Msz-ln18\/25\/35\/50\/60vg2w-et2 Msz-ln18\/25\/35\/50\/60vg2w-et2 Firmware Msz-ln18\/25\/35\/50vg2w-sc1 Msz-ln18\/25\/35\/50vg2w-sc1 Firmware Msz-ln25\/35\/50\/60vg2b-a2 Msz-ln25\/35\/50\/60vg2b-a2 Firmware Msz-ln25\/35\/50\/60vg2b-er2 Msz-ln25\/35\/50\/60vg2b-er2 Firmware Msz-ln25\/35\/50\/60vg2b-er3 Msz-ln25\/35\/50\/60vg2b-er3 Firmware Msz-ln25\/35\/50\/60vg2b-et2 Msz-ln25\/35\/50\/60vg2b-et2 Firmware Msz-ln25\/35\/50\/60vg2b-et3 Msz-ln25\/35\/50\/60vg2b-et3 Firmware Msz-ln25\/35\/50\/60vg2r-a2 Msz-ln25\/35\/50\/60vg2r-a2 Firmware Msz-ln25\/35\/50\/60vg2r-er2 Msz-ln25\/35\/50\/60vg2r-er2 Firmware Msz-ln25\/35\/50\/60vg2r-er3 Msz-ln25\/35\/50\/60vg2r-er3 Firmware Msz-ln25\/35\/50\/60vg2r-et2 Msz-ln25\/35\/50\/60vg2r-et2 Firmware Msz-ln25\/35\/50\/60vg2r-et3 Msz-ln25\/35\/50\/60vg2r-et3 Firmware Msz-ln25\/35\/50\/60vg2v-a2 Msz-ln25\/35\/50\/60vg2v-a2 Firmware Msz-ln25\/35\/50\/60vg2v-er2 Msz-ln25\/35\/50\/60vg2v-er2 Firmware Msz-ln25\/35\/50\/60vg2v-er3 Msz-ln25\/35\/50\/60vg2v-er3 Firmware Msz-ln25\/35\/50\/60vg2v-et2 Msz-ln25\/35\/50\/60vg2v-et2 Firmware Msz-ln25\/35\/50\/60vg2v-et3 Msz-ln25\/35\/50\/60vg2v-et3 Firmware Msz-ln25\/35\/50\/60vg2w-er3 Msz-ln25\/35\/50\/60vg2w-er3 Firmware Msz-ln25\/35\/50\/60vg2w-et3 Msz-ln25\/35\/50\/60vg2w-et3 Firmware Msz-ln25\/35\/50vg2b-en2 Msz-ln25\/35\/50vg2b-en2 Firmware Msz-ln25\/35\/50vg2b-sc1 Msz-ln25\/35\/50vg2b-sc1 Firmware Msz-ln25\/35\/50vg2r-en2 Msz-ln25\/35\/50vg2r-en2 Firmware Msz-ln25\/35\/50vg2r-sc1 Msz-ln25\/35\/50vg2r-sc1 Firmware Msz-ln25\/35\/50vg2v-en2 Msz-ln25\/35\/50vg2v-en2 Firmware Msz-ln25\/35\/50vg2v-sc1 Msz-ln25\/35\/50vg2v-sc1 Firmware Msz-ln25\/35\/50vg2w-en2 Msz-ln25\/35\/50vg2w-en2 Firmware Msz-rw25\/35\/50vg-e1 Msz-rw25\/35\/50vg-e1 Firmware Msz-rw25\/35\/50vg-er1 Msz-rw25\/35\/50vg-er1 Firmware Msz-rw25\/35\/50vg-et1 Msz-rw25\/35\/50vg-et1 Firmware Msz-rw25\/35\/50vg-sc1 Msz-rw25\/35\/50vg-sc1 Firmware Msz-wx18\/20\/25vfk Msz-wx18\/20\/25vfk Firmware Msz-zy09\/12\/18vfk Msz-zy09\/12\/18vfk Firmware S-mac-002if S-mac-002if Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: Mitsubishi

Published:

Updated: 2025-05-01T14:38:35.036Z

Reserved: 2022-06-14T00:00:00.000Z

Link: CVE-2022-33322

cve-icon Vulnrichment

Updated: 2024-08-03T08:09:21.294Z

cve-icon NVD

Status : Modified

Published: 2022-11-08T20:15:11.017

Modified: 2025-05-01T15:15:55.120

Link: CVE-2022-33322

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses