Mitsubishi Protocol Flaw Exposes Industrial Control Traffic to On-Segment Tampering
CVE-2026-13584 in Mitsubishi CC-Link IE TSN lets on-segment attackers tamper control traffic, disrupt operations or cause downtime. No patch yet.
Text generated by artificial intelligence, published without human review. AI transparency
Illustrative image generated with AI
A message-integrity weakness in Mitsubishi Electric’s CC-Link IE TSN ecosystem could allow an attacker on the same network segment to manipulate industrial communication traffic, disrupt control functions, or cause equipment to become unavailable.
Tracked as CVE-2026-13584, the vulnerability affects a broad inventory of controllers, motion systems, servo drives, remote modules, operator interfaces, communication components, software, and development kits. CISA assigned it a CVSS v3 score of 7.1.
As of September 18, 2026, no fixed versions, patches, configuration workarounds, or model-specific upgrade paths have been disclosed. Confirmed exploitation has not been reported.
Crafted packets can interfere with control communications
CVE-2026-13584 is classified as CWE-924, or improper enforcement of message integrity during transmission over a communication channel. The weakness resides in products implementing or supporting Mitsubishi Electric’s CC-Link IE TSN Communication Protocol (Update A).
An attacker must first gain access to the same network segment as the affected equipment. The attack involves sending specially crafted packets under particular timing conditions, potentially allowing communication data to be altered or interfered with during transmission.
The timing requirement may make attacks less reliable, but successful exploitation could have direct operational consequences. Manipulated messages may prevent a controller from performing its intended function, cause connected equipment to operate incorrectly, or trigger a denial-of-service condition.
This is not described as an Internet-native or unauthenticated remote attack. Available information does not establish whether protocol authentication is required, nor does it identify any confidentiality impact or data-exfiltration capability.
The principal risk is integrity and availability inside an industrial network.
Affected equipment spans multiple control layers
Every listed product carries the version designation vers:all/*. Operators should therefore treat all versions of the named models as affected unless Mitsubishi Electric provides narrower information.
The affected MELSEC MX controllers are:
- MX-R: MXR300-16, MXR300-32, MXR300-64, MXR500-128, and MXR500-256
- MX-F: MXF100-8-N32, MXF100-8-P32, MXF100-16-N32, MXF100-16-P32, MXF100S-N32, MXF100S-P32, MXF100S-8-N32, MXF100S-8-P32, MXF100S-16-N32, and MXF100S-16-P32
Master/local modules and interface boards include RJ71GN11-T2, RJ71GN11-SX, RJ71GN11-EIP, FX5-CCLGN-MS, NZ81GN11-SX, and NZ81GN11-T2.
Motion products include RD78G4, RD78G8, RD78G16, RD78G64, RD78GHV, RD78GHW, FX5-40SSC-G, FX5-80SSC-G, LD78G4, LD78G16, MR-EM441G, SWM-G, and SWM-G-N1.
The affected block-type remote modules are:
- NZ2GN2S1-32D, NZ2GN2S1-32T, NZ2GN2S1-32TE, NZ2GN2S1-32DT, NZ2GN2S1-32DTE
- NZ2GN2B1-32D, NZ2GN2B1-32T, NZ2GN2B1-32TE, NZ2GN2B1-32DT, NZ2GN2B1-32DTE
- NZ2GNCF1-32D, NZ2GNCF1-32T, NZ2GNCE3-32D, NZ2GNCE3-32DT
- NZ2GN12A4-16D, NZ2GN12A4-16DE, NZ2GN12A2-16T, NZ2GN12A2-16TE, NZ2GN12A42-16DT, NZ2GN12A42-16DTE
- NZ2GN2S1-16D, NZ2GN2S1-16T, NZ2GN2S1-16TE, NZ2GN2B1-16D, NZ2GN2B1-16T, and NZ2GN2B1-16TE
Safety-function modules include NZ2GNSS2-8D, NZ2GNSS2-8D-K, NZ2GNSS2-8TE, NZ2GNSS2-8TE-K, NZ2GNSS2-16DTE, NZ2GNSS2-16DTE-K, NZ2GNS12A2-14DT, and NZ2GNS12A2-16DTE.
Converter, coupler, FPGA, and measurement products comprise NZ2GN2S-60AD4, NZ2GN2B-60AD4, NZ2GN2S-60DA4, NZ2GN2B-60DA4, NZ2FT-GN, NZ2GN2S-D41P01, NZ2GN2S-D41D01, NZ2GN2S-D41PD02, LM7-1LG, and LM7-2LG.
Servo systems include MR-J5-G, MR-J5W-G, MR-J5-G-HS, MR-J5-G-RJ, MR-J5-G-LL, MR-J5D-G4, MR-MD333G, MR-JET-G, and MR-JET-G4-HS.
Also affected are linear-track modules MTR-SCU00-4G and MTR-SCU00-PG, plus inverter products FR-A8NCG, FR-A8NCG-S, FR-A800-GN, FR-E800-E, and FR-E800-SCE.
Robots, operator terminals, software, and silicon are also exposed
The inventory extends beyond conventional programmable controllers. It includes the industrial robot controller network card 2F-DQ535-TSN, expansion unit FCU8-EX569, bridge modules NZ2GN-GFB and NZ2AW1GNAL, and energy-measurement communication unit EMU4-CM-TSN.
Affected GOT3000 products are GT3715-FHCBD, GT3712-WXCBD, GT3715-XRBA, GT3715-XRBD, GT3712-XRBA, GT3712-XRBD, GT3710-XRBA, GT3710-XRBD, GT3708-XRBA, and GT3708-XRBD. The GT25-J71GN13-T2 communication unit is also listed.
Software and development components include:
- SW1DND-CCIETCT-M CC-Link IE TSN Communication Software for Windows
- SW1DNN-VIMA-M MELSOFT VIMA analysis software
- NZ2KT-NPETNG51 DeviceKit
- NZ2GACP620-60, NZ2GACP620-300, NZ2GACP621-90, and NZ2GACP621-720 communication LSIs
- SW1DNN-GN610SRC-M master/local module SDK
- SW1DNC-GNSDK1S-M and SW1DNC-GNSDK2S-M remote-station SDKs
This breadth complicates asset discovery. Vulnerable protocol implementations may be embedded in field modules, software packages, interface boards, or low-level communication components rather than appearing as standalone network devices.
Manufacturing operators face integrity and availability risks
CISA’s industrial control systems advisory identifies worldwide deployment in the Critical Manufacturing sector. Mitsubishi Electric is headquartered in Japan.
Consequences depend on the role of the targeted component. Tampered traffic affecting motion controllers, drives, robots, or remote input/output modules could produce incorrect equipment behavior. Attacks against communication units or software components may instead disrupt coordination between control layers.
Safety-function modules are among the listed products, but no specific safety-system outcome has been disclosed. Operators should not assume that ordinary IT containment procedures are safe to apply without operational testing.
There are no reported indicators tied to a specific attack campaign. No threat actor, exploit code, or confirmed exploitation has been identified.
CVE-2026-13584 is not stated to be in CISA’s Known Exploited Vulnerabilities catalog, and no KEV remediation deadline has been provided. Available information also does not establish a recent pattern of other Mitsubishi Electric vulnerabilities entering KEV.
Defenders should isolate protocol segments while awaiting fixes
With no published remediation version, network controls provide the most immediate risk reduction. Asset owners should first identify every listed model, including communication boards, development kits, Windows software, and LSIs incorporated into other products.
Access to CC-Link IE TSN segments should be limited to authorized controllers, engineering workstations, and necessary industrial hosts. Enterprise systems, Internet-facing services, and untrusted devices should not share those segments or gain unrestricted routed access to them.
Monitoring should focus on:
- Unusual CC-Link IE TSN packet timing or traffic bursts
- Malformed or unexpected protocol messages
- Communication-integrity errors
- Unplanned control-state changes
- Unexpected controller, module, drive, or operator-terminal resets
- Intermittent loss of communication or unexplained denial-of-service conditions
Network captures and controller logs should be preserved when anomalies occur. Because exploitation depends partly on timing, isolated events may otherwise be difficult to reconstruct.
Any future firmware, software, controller, or module update should be coordinated with Mitsubishi Electric and the responsible operational-technology team. Changes should be tested in a representative environment before production deployment, particularly where motion, robotics, drives, safety functions, or continuous manufacturing processes are involved.
Sources
This article is an original reworking based on the sources below.
