Inea's vulnerability profile centers on a narrow embedded product line focused on remote-terminal-unit (RTU) devices and associated firmware, which sit in critical infrastructure and industrial control deployments. The vulnerabilities affecting these products skew strongly toward critical severity and frequently acquire public exploit code, with exposure recurs through OS command injection, hard-coded credentials, forced browsing, authentication bypass, and cross-site scripting—a pattern reflecting the authentication and input-validation demands of exposed network interfaces in operational technology environments. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Inea over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-14931CRITICAL An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote OS Command Injection vulnerabi | Oct 28, 2019 | 9.8 | 72 | NO | YES |
CVE-2019-14927HIGH An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote configuration download vulnera | Oct 28, 2019 | 7.5 | 56 | NO | YES |
CVE-2019-14928MEDIUM An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A number of stored cross-site script (XSS) vulnerabiliti | Oct 28, 2019 | 5.4 | 39 | NO | NO |
CVE-2023-2131CRITICAL Versions of INEA ME RTU firmware prior to 3.36 are vulnerable to OS command injection, which could allow an attacker to remotely execute arbitrary code. | Apr 20, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-29155CRITICAL Versions of INEA ME RTU firmware 3.36b and prior do not require authentication to the "root" account on the host system of the device. This could allow an attacker to obtain admin- | Nov 20, 2023 | 9.8 | 30 | NO | NO |
CVE-2019-14930CRITICAL An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Undocumented hard-coded user passwords for root, ineaadm | Oct 28, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-14929CRITICAL An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Stored cleartext passwords could allow an unauthenticate | Oct 28, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-14926CRITICAL An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Hard-coded SSH keys allow an attacker to gain unauthoris | Oct 28, 2019 | 9.8 | 28 | NO | NO |
CVE-2023-35762CRITICAL
Versions of INEA ME RTU firmware 3.36b and prior are vulnerable to operating system (OS) command injection, which could allow remote code execution.
| Nov 20, 2023 | 9.8 | 27 | NO | NO |
CVE-2019-14925MEDIUM An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A world-readable /usr/smartrtu/init/settings.xml configu | Oct 28, 2019 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Inea.
Media articles that mention a CVE ID that affects a product developed by Inea — matched by CVE ID, not by vendor name.