CVE-2026-5667
Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan)
Wireless LAN Adapters for Room Air Conditioners (for Japan and outside Japan)
Wireless LAN Adapters for Packaged Air Conditioners (for Japan and outside Japan)
Refrigerators (for Japan)
Heat Pump Water Heaters / HEMS-Compatible Adapters / Wireless LAN Adapters (for Japan)
Bathroom Dryer / Heater / Ventilation Systems (for Japan)
Adapters for Airflow Ventilation Systems, Heat Pump Chilled / Hot Water Systems, and Ventilation / Air-Conditioning System Air Resorts (for Japan)
Lossnay Central Ventilation Systems (for Japan)
Smart Switches for Ventilation Fans and Lossnay (for Japan)
IH Cooking Heaters (for Japan)
and Rice Cookers (for Japan) allows an attacker within Wi-Fi radio range of an affected product to access the affected product using a hard-coded SSID and password, thereby obtaining device data such as operation status, room set temperature, and room temperature.
changing the air-conditioner or Wi-Fi settings.
or causing Wi-Fi communication to enter a denial-of-service (DoS) condition.
- ⚠ NVD has not scored this CVE yet - manual triage required (common for recent CVEs)
ATT&CK techniques
2Techniques this CVE enables - linked via CWECAPECATT&CK. High◆ = named directly in ATT&CK or Nuclei templates.
▤ Build a SIEM detection for these techniquesCAPEC attack patterns
2Attack patterns this CVE enables - the bridge from weakness to ATT&CK technique.