Cross-site scripting vulnerability in Mitsubishi Electric consumer electronics products (Air Conditioning, Wi-Fi Interface, Refrigerator, HEMS adapter, Remote control with Wi-Fi Interface, BATHROOM THERMO VENTILATOR, Rice cooker, Mitsubishi Electric HEMS control adapter, Energy Recovery Ventilator, Smart Switch and Air Purifier) allows a remote unauthenticated attacker to execute an malicious script on a user's browser to disclose information, etc. The wide range of models/versions of Mitsubishi Electric consumer electronics products are affected by this vulnerability. As for the affected product models/versions, see the Mitsubishi Electric's advisory which is listed in [References] section.

Project Subscriptions

Vendors Products
Mitsubishielectric Subscribe
Ma-ew85s-e Subscribe
Ma-ew85s-e Firmware Subscribe
Ma-ew85s-uk Subscribe
Ma-ew85s-uk Firmware Subscribe
Mac-507if-e Subscribe
Mac-507if-e Firmware Subscribe
Mac-587if-e Subscribe
Mac-587if-e Firmware Subscribe
Mac-587if2-e Subscribe
Mac-587if2-e Firmware Subscribe
Mac-588if-e Subscribe
Mac-588if-e Firmware Subscribe
Mfz-gxt50\/60\/73vfk Subscribe
Mfz-gxt50\/60\/73vfk Firmware Subscribe
Mfz-xt50\/60vfk Subscribe
Mfz-xt50\/60vfk Firmware Subscribe
Msxy-fp05\/07\/10\/13\/18\/20\/24vgk-sg1 Subscribe
Msxy-fp05\/07\/10\/13\/18\/20\/24vgk-sg1 Firmware Subscribe
Msy-gp10\/13\/15\/18\/20\/24vfk-sg1 Subscribe
Msy-gp10\/13\/15\/18\/20\/24vfk-sg1 Firmware Subscribe
Msz-ap15\/20\/25\/35\/42\/50\/60\/71vgk-e2 Subscribe
Msz-ap15\/20\/25\/35\/42\/50\/60\/71vgk-e2 Firmware Subscribe
Msz-ap15\/20\/25\/35\/42\/50\/60\/71vgk-er2 Subscribe
Msz-ap15\/20\/25\/35\/42\/50\/60\/71vgk-er2 Firmware Subscribe
Msz-ap15\/20\/25\/35\/42\/50\/60\/71vgk-et2 Subscribe
Msz-ap15\/20\/25\/35\/42\/50\/60\/71vgk-et2 Firmware Subscribe
Msz-ap22\/25\/35\/42\/50\/60\/71\/80vgkd-a2 Subscribe
Msz-ap22\/25\/35\/42\/50\/60\/71\/80vgkd-a2 Firmware Subscribe
Msz-ap22\/25\/35\/42\/50\/61\/70\/80vgkd-a1 Subscribe
Msz-ap22\/25\/35\/42\/50\/61\/70\/80vgkd-a1 Firmware Subscribe
Msz-ap25\/35\/42\/50\/60\/71vgk-e3 Subscribe
Msz-ap25\/35\/42\/50\/60\/71vgk-e3 Firmware Subscribe
Msz-ap25\/35\/42\/50\/60\/71vgk-er3 Subscribe
Msz-ap25\/35\/42\/50\/60\/71vgk-er3 Firmware Subscribe
Msz-ap25\/35\/42\/50\/60\/71vgk-et3 Subscribe
Msz-ap25\/35\/42\/50\/60\/71vgk-et3 Firmware Subscribe
Msz-ap25\/35\/42\/50vgk-e1 Subscribe
Msz-ap25\/35\/42\/50vgk-e1 Firmware Subscribe
Msz-ap25\/35\/42\/50vgk-e7 Subscribe
Msz-ap25\/35\/42\/50vgk-e7 Firmware Subscribe
Msz-ap25\/35\/42\/50vgk-e8 Subscribe
Msz-ap25\/35\/42\/50vgk-e8 Firmware Subscribe
Msz-ap25\/35\/42\/50vgk-en1 Subscribe
Msz-ap25\/35\/42\/50vgk-en1 Firmware Subscribe
Msz-ap25\/35\/42\/50vgk-en2 Subscribe
Msz-ap25\/35\/42\/50vgk-en2 Firmware Subscribe
Msz-ap25\/35\/42\/50vgk-en3 Subscribe
Msz-ap25\/35\/42\/50vgk-en3 Firmware Subscribe
Msz-ap25\/35\/42\/50vgk-er1 Subscribe
Msz-ap25\/35\/42\/50vgk-er1 Firmware Subscribe
Msz-ap25\/35\/42\/50vgk-et1 Subscribe
Msz-ap25\/35\/42\/50vgk-et1 Firmware Subscribe
Msz-ay25\/35\/42\/50vgk-e1 Subscribe
Msz-ay25\/35\/42\/50vgk-e1 Firmware Subscribe
Msz-ay25\/35\/42\/50vgk-e6 Subscribe
Msz-ay25\/35\/42\/50vgk-e6 Firmware Subscribe
Msz-ay25\/35\/42\/50vgk-er1 Subscribe
Msz-ay25\/35\/42\/50vgk-er1 Firmware Subscribe
Msz-ay25\/35\/42\/50vgk-et1 Subscribe
Msz-ay25\/35\/42\/50vgk-et1 Firmware Subscribe
Msz-ay25\/35\/42\/50vgk-sc1 Subscribe
Msz-ay25\/35\/42\/50vgk-sc1 Firmware Subscribe
Msz-ay25\/35\/42\/50vgkp-e6 Subscribe
Msz-ay25\/35\/42\/50vgkp-e6 Firmware Subscribe
Msz-ay25\/35\/42\/50vgkp-er1 Subscribe
Msz-ay25\/35\/42\/50vgkp-er1 Firmware Subscribe
Msz-ay25\/35\/42\/50vgkp-et1 Subscribe
Msz-ay25\/35\/42\/50vgkp-et1 Firmware Subscribe
Msz-ay25\/35\/42\/50vgkp-sc1 Subscribe
Msz-ay25\/35\/42\/50vgkp-sc1 Firmware Subscribe
Msz-bt20\/25\/35\/50vgk-e1 Subscribe
Msz-bt20\/25\/35\/50vgk-e1 Firmware Subscribe
Msz-bt20\/25\/35\/50vgk-e2 Subscribe
Msz-bt20\/25\/35\/50vgk-e2 Firmware Subscribe
Msz-bt20\/25\/35\/50vgk-e3 Subscribe
Msz-bt20\/25\/35\/50vgk-e3 Firmware Subscribe
Msz-bt20\/25\/35\/50vgk-er1 Subscribe
Msz-bt20\/25\/35\/50vgk-er1 Firmware Subscribe
Msz-bt20\/25\/35\/50vgk-er2 Subscribe
Msz-bt20\/25\/35\/50vgk-er2 Firmware Subscribe
Msz-bt20\/25\/35\/50vgk-et1 Subscribe
Msz-bt20\/25\/35\/50vgk-et1 Firmware Subscribe
Msz-bt20\/25\/35\/50vgk-et2 Subscribe
Msz-bt20\/25\/35\/50vgk-et2 Firmware Subscribe
Msz-bt20\/25\/35\/50vgk-et3 Subscribe
Msz-bt20\/25\/35\/50vgk-et3 Firmware Subscribe
Msz-ef18\/22\/25\/35\/42\/50vgkb-e1 Subscribe
Msz-ef18\/22\/25\/35\/42\/50vgkb-e1 Firmware Subscribe
Msz-ef18\/22\/25\/35\/42\/50vgkb-e2 Subscribe
Msz-ef18\/22\/25\/35\/42\/50vgkb-e2 Firmware Subscribe
Msz-ef18\/22\/25\/35\/42\/50vgks-e1 Subscribe
Msz-ef18\/22\/25\/35\/42\/50vgks-e1 Firmware Subscribe
Msz-ef18\/22\/25\/35\/42\/50vgks-e2 Subscribe
Msz-ef18\/22\/25\/35\/42\/50vgks-e2 Firmware Subscribe
Msz-ef18\/22\/25\/35\/42\/50vgkw-e1 Subscribe
Msz-ef18\/22\/25\/35\/42\/50vgkw-e1 Firmware Subscribe
Msz-ef18\/22\/25\/35\/42\/50vgkw-e2 Subscribe
Msz-ef18\/22\/25\/35\/42\/50vgkw-e2 Firmware Subscribe
Msz-ef22\/25\/35\/42\/50vgkb-a1 Subscribe
Msz-ef22\/25\/35\/42\/50vgkb-a1 Firmware Subscribe
Msz-ef22\/25\/35\/42\/50vgkb-er1 Subscribe
Msz-ef22\/25\/35\/42\/50vgkb-er1 Firmware Subscribe
Msz-ef22\/25\/35\/42\/50vgkb-er2 Subscribe
Msz-ef22\/25\/35\/42\/50vgkb-er2 Firmware Subscribe
Msz-ef22\/25\/35\/42\/50vgkb-et1 Subscribe
Msz-ef22\/25\/35\/42\/50vgkb-et1 Firmware Subscribe
Msz-ef22\/25\/35\/42\/50vgkb-et2 Subscribe
Msz-ef22\/25\/35\/42\/50vgkb-et2 Firmware Subscribe
Msz-ef22\/25\/35\/42\/50vgks-a1 Subscribe
Msz-ef22\/25\/35\/42\/50vgks-a1 Firmware Subscribe
Msz-ef22\/25\/35\/42\/50vgks-er1 Subscribe
Msz-ef22\/25\/35\/42\/50vgks-er1 Firmware Subscribe
Msz-ef22\/25\/35\/42\/50vgks-er2 Subscribe
Msz-ef22\/25\/35\/42\/50vgks-er2 Firmware Subscribe
Msz-ef22\/25\/35\/42\/50vgks-et1 Subscribe
Msz-ef22\/25\/35\/42\/50vgks-et1 Firmware Subscribe
Msz-ef22\/25\/35\/42\/50vgks-et2 Subscribe
Msz-ef22\/25\/35\/42\/50vgks-et2 Firmware Subscribe
Msz-ef22\/25\/35\/42\/50vgkw-a1 Subscribe
Msz-ef22\/25\/35\/42\/50vgkw-a1 Firmware Subscribe
Msz-ef22\/25\/35\/42\/50vgkw-er1 Subscribe
Msz-ef22\/25\/35\/42\/50vgkw-er1 Firmware Subscribe
Msz-ef22\/25\/35\/42\/50vgkw-er2 Subscribe
Msz-ef22\/25\/35\/42\/50vgkw-er2 Firmware Subscribe
Msz-ef22\/25\/35\/42\/50vgkw-et1 Subscribe
Msz-ef22\/25\/35\/42\/50vgkw-et1 Firmware Subscribe
Msz-ef22\/25\/35\/42\/50vgkw-et2 Subscribe
Msz-ef22\/25\/35\/42\/50vgkw-et2 Firmware Subscribe
Msz-exa09\/12vak Subscribe
Msz-exa09\/12vak Firmware Subscribe
Msz-eza09\/12vak Subscribe
Msz-eza09\/12vak Firmware Subscribe
Msz-ft25\/35\/50vgk-e1 Subscribe
Msz-ft25\/35\/50vgk-e1 Firmware Subscribe
Msz-ft25\/35\/50vgk-e2 Subscribe
Msz-ft25\/35\/50vgk-e2 Firmware Subscribe
Msz-ft25\/35\/50vgk-et1 Subscribe
Msz-ft25\/35\/50vgk-et1 Firmware Subscribe
Msz-ft25\/35\/50vgk-sc1 Subscribe
Msz-ft25\/35\/50vgk-sc1 Firmware Subscribe
Msz-ft25\/35\/50vgk-sc2 Subscribe
Msz-ft25\/35\/50vgk-sc2 Firmware Subscribe
Msz-gzy09\/12\/18vfk Subscribe
Msz-gzy09\/12\/18vfk Firmware Subscribe
Msz-hr25\/35\/42\/50\/60\/71vfk-e1 Subscribe
Msz-hr25\/35\/42\/50\/60\/71vfk-e1 Firmware Subscribe
Msz-hr25\/35\/42\/50\/60\/71vfk-er1 Subscribe
Msz-hr25\/35\/42\/50\/60\/71vfk-er1 Firmware Subscribe
Msz-hr25\/35\/42\/50\/60\/71vfk-et1 Subscribe
Msz-hr25\/35\/42\/50\/60\/71vfk-et1 Firmware Subscribe
Msz-hr25\/35\/42\/50vfk-e6 Subscribe
Msz-hr25\/35\/42\/50vfk-e6 Firmware Subscribe
Msz-ky09\/12\/18vfk Subscribe
Msz-ky09\/12\/18vfk Firmware Subscribe
Msz-ln18\/25\/35\/50\/60vg2b-e2 Subscribe
Msz-ln18\/25\/35\/50\/60vg2b-e2 Firmware Subscribe
Msz-ln18\/25\/35\/50\/60vg2b-e3 Subscribe
Msz-ln18\/25\/35\/50\/60vg2b-e3 Firmware Subscribe
Msz-ln18\/25\/35\/50\/60vg2r-e2 Subscribe
Msz-ln18\/25\/35\/50\/60vg2r-e2 Firmware Subscribe
Msz-ln18\/25\/35\/50\/60vg2r-e3 Subscribe
Msz-ln18\/25\/35\/50\/60vg2r-e3 Firmware Subscribe
Msz-ln18\/25\/35\/50\/60vg2v-e2 Subscribe
Msz-ln18\/25\/35\/50\/60vg2v-e2 Firmware Subscribe
Msz-ln18\/25\/35\/50\/60vg2v-e3 Subscribe
Msz-ln18\/25\/35\/50\/60vg2v-e3 Firmware Subscribe
Msz-ln18\/25\/35\/50\/60vg2w-e2 Subscribe
Msz-ln18\/25\/35\/50\/60vg2w-e2 Firmware Subscribe
Msz-ln18\/25\/35\/50\/60vg2w-e3 Subscribe
Msz-ln18\/25\/35\/50\/60vg2w-e3 Firmware Subscribe
Msz-ln18\/25\/35\/50\/60vg2w-er2 Subscribe
Msz-ln18\/25\/35\/50\/60vg2w-er2 Firmware Subscribe
Msz-ln18\/25\/35\/50\/60vg2w-et2 Subscribe
Msz-ln18\/25\/35\/50\/60vg2w-et2 Firmware Subscribe
Msz-ln18\/25\/35\/50vg2w-sc1 Subscribe
Msz-ln18\/25\/35\/50vg2w-sc1 Firmware Subscribe
Msz-ln25\/35\/50\/60vg2b-a2 Subscribe
Msz-ln25\/35\/50\/60vg2b-a2 Firmware Subscribe
Msz-ln25\/35\/50\/60vg2b-er2 Subscribe
Msz-ln25\/35\/50\/60vg2b-er2 Firmware Subscribe
Msz-ln25\/35\/50\/60vg2b-er3 Subscribe
Msz-ln25\/35\/50\/60vg2b-er3 Firmware Subscribe
Msz-ln25\/35\/50\/60vg2b-et2 Subscribe
Msz-ln25\/35\/50\/60vg2b-et2 Firmware Subscribe
Msz-ln25\/35\/50\/60vg2b-et3 Subscribe
Msz-ln25\/35\/50\/60vg2b-et3 Firmware Subscribe
Msz-ln25\/35\/50\/60vg2r-a2 Subscribe
Msz-ln25\/35\/50\/60vg2r-a2 Firmware Subscribe
Msz-ln25\/35\/50\/60vg2r-er2 Subscribe
Msz-ln25\/35\/50\/60vg2r-er2 Firmware Subscribe
Msz-ln25\/35\/50\/60vg2r-er3 Subscribe
Msz-ln25\/35\/50\/60vg2r-er3 Firmware Subscribe
Msz-ln25\/35\/50\/60vg2r-et2 Subscribe
Msz-ln25\/35\/50\/60vg2r-et2 Firmware Subscribe
Msz-ln25\/35\/50\/60vg2r-et3 Subscribe
Msz-ln25\/35\/50\/60vg2r-et3 Firmware Subscribe
Msz-ln25\/35\/50\/60vg2v-a2 Subscribe
Msz-ln25\/35\/50\/60vg2v-a2 Firmware Subscribe
Msz-ln25\/35\/50\/60vg2v-er2 Subscribe
Msz-ln25\/35\/50\/60vg2v-er2 Firmware Subscribe
Msz-ln25\/35\/50\/60vg2v-er3 Subscribe
Msz-ln25\/35\/50\/60vg2v-er3 Firmware Subscribe
Msz-ln25\/35\/50\/60vg2v-et2 Subscribe
Msz-ln25\/35\/50\/60vg2v-et2 Firmware Subscribe
Msz-ln25\/35\/50\/60vg2v-et3 Subscribe
Msz-ln25\/35\/50\/60vg2v-et3 Firmware Subscribe
Msz-ln25\/35\/50\/60vg2w-er3 Subscribe
Msz-ln25\/35\/50\/60vg2w-er3 Firmware Subscribe
Msz-ln25\/35\/50\/60vg2w-et3 Subscribe
Msz-ln25\/35\/50\/60vg2w-et3 Firmware Subscribe
Msz-ln25\/35\/50vg2b-en2 Subscribe
Msz-ln25\/35\/50vg2b-en2 Firmware Subscribe
Msz-ln25\/35\/50vg2b-sc1 Subscribe
Msz-ln25\/35\/50vg2b-sc1 Firmware Subscribe
Msz-ln25\/35\/50vg2r-en2 Subscribe
Msz-ln25\/35\/50vg2r-en2 Firmware Subscribe
Msz-ln25\/35\/50vg2r-sc1 Subscribe
Msz-ln25\/35\/50vg2r-sc1 Firmware Subscribe
Msz-ln25\/35\/50vg2v-en2 Subscribe
Msz-ln25\/35\/50vg2v-en2 Firmware Subscribe
Msz-ln25\/35\/50vg2v-sc1 Subscribe
Msz-ln25\/35\/50vg2v-sc1 Firmware Subscribe
Msz-ln25\/35\/50vg2w-en2 Subscribe
Msz-ln25\/35\/50vg2w-en2 Firmware Subscribe
Msz-rw25\/35\/50vg-e1 Subscribe
Msz-rw25\/35\/50vg-e1 Firmware Subscribe
Msz-rw25\/35\/50vg-er1 Subscribe
Msz-rw25\/35\/50vg-er1 Firmware Subscribe
Msz-rw25\/35\/50vg-et1 Subscribe
Msz-rw25\/35\/50vg-et1 Firmware Subscribe
Msz-rw25\/35\/50vg-sc1 Subscribe
Msz-rw25\/35\/50vg-sc1 Firmware Subscribe
Msz-wx18\/20\/25vfk Subscribe
Msz-wx18\/20\/25vfk Firmware Subscribe
Msz-zy09\/12\/18vfk Subscribe
Msz-zy09\/12\/18vfk Firmware Subscribe
S-mac-002if Subscribe
S-mac-002if Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-36365 Cross-site scripting vulnerability in Mitsubishi Electric consumer electronics products (Air Conditioning, Wi-Fi Interface, Refrigerator, HEMS adapter, Remote control with Wi-Fi Interface, BATHROOM THERMO VENTILATOR, Rice cooker, Mitsubishi Electric HEMS control adapter, Energy Recovery Ventilator, Smart Switch and Air Purifier) allows a remote unauthenticated attacker to execute an malicious script on a user's browser to disclose information, etc. The wide range of models/versions of Mitsubishi Electric consumer electronics products are affected by this vulnerability. As for the affected product models/versions, see the Mitsubishi Electric's advisory which is listed in [References] section.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 01 May 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mitsubishi

Published:

Updated: 2025-05-01T14:38:35.036Z

Reserved: 2022-06-14T00:00:00.000Z

Link: CVE-2022-33322

cve-icon Vulnrichment

Updated: 2024-08-03T08:09:21.294Z

cve-icon NVD

Status : Modified

Published: 2022-11-08T20:15:11.017

Modified: 2025-05-01T15:15:55.120

Link: CVE-2022-33322

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses