Skip to content
Book a Demo

A Wake-Up Call for Building HVAC Security

Neeve has released a guide to help understand why unsecured OT systems remain a top vulnerability and what building operators must do now.

In May 2025, Mitsubishi Electric disclosed a critical vulnerability (CVE-2025-3699) in its commercial HVAC systems, scoring 9.8 on the CVSS scale, the highest possible rating for severity.

Discovered by security researcher Mihály Csonka, the flaw is a Missing Authentication for Critical Function, allowing remote attackers to:

  • Bypass authentication entirely
  • Take full control of HVAC systems
  • Access sensitive building data
  • Tamper with firmware—without user interaction

Download the PDF