CVE-2018-16061: Mitsubishielectric Smartrtu Firmware

Medium severity, CVSS 6.1. EPSS: 4% chance of exploitation in the next 30 days.

Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php.

Affected products

Published 2021-10-15. Last modified 2026-06-17.