Skip to content

Security1 publisher2 min readPublished

Crafted CC-Link IE TSN packets can stall Mitsubishi Electric controllers from inside the same segment

CVE-2026-13584 affects every version Mitsubishi Electric shipped of at least 45 parts, including MELSEC MX controllers and remote I/O blocks. The precondition CISA names is access to the same network segment.

The Watch · Security desk

What happened

  • CISA has published its Mitsubishi Electric CC-Link IE TSN Communication Protocol advisory as Update A, covering a flaw in the protocol implementation used across the vendor's control hardware.
  • The outcome CISA describes is a denial of service, with the affected device's control function interfered with or the device operating incorrectly.
  • The single identifier CVE-2026-13584 covers MELSEC MX-R and MX-F controllers, RJ71GN11 master/local modules, RD78G motion modules and NZ2GN remote I/O, with all versions listed as affected.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure The check reaches below the controller rack: block-type remote I/O modules and a motion control board are in scope, so field cabinet hardware needs verifying too.
  • capability Adjacency is the only access CISA names, so one compromised device on the CC-Link segment is enough.
  • decision With no fixed version published yet, OT owners are deciding which segments to fence and who may attach hardware.

One CVE covering eight product families points at shared protocol code. The same CC-Link IE TSN implementation sits in the MX-R and MX-F controllers, in the RJ71GN11 master/local modules, in the RD78G motion modules and in the NZ2GN block-type remote I/O [5][7][9][12].

Counted out of CISA's list: five MX-R controllers, ten MX-F, four master/local modules, two interface boards, eight motion modules, two MELSEC iQ-L motion modules, one motion control board, thirteen block-type remote modules [5][6][7][8][9][10][11][12]. That is 45 part numbers, and the list is still running where the published text breaks off in the middle of an entry [13][12].

An internet scan does not find this one. The precondition is access to the same network segment, and the crafted packets have to land under specific timing conditions [3]. What the attacker gets is data tampering that turns into a denial of service, either by interfering with the control function or by making the device operate incorrectly [4]. The attacker needs a foothold first, and something already attached to the control network to send from.

The impact class lands harder because of what is on the list. Motion modules and a motion control board are in scope [9][11], as are the block-type remote modules that carry field I/O [12]. Verifying those means reading part numbers in racks and field cabinets.

Version triage is unavailable. Every entry is marked as affecting all versions [2], so there is no firmware level that takes a device off the list. The advisory is labelled Update A [16], which means the model list has been revised at least once since first publication and any inventory matched against the original needs a second pass.

The published text stops in the block-type remote module list, before any mitigation section, and lists no fixed firmware version [15]. Until Mitsubishi Electric publishes one, the controls that exist are the boundary around the CC-Link segment and the rules about who gets to plug something into it.

What to watch

  • Whether Mitsubishi Electric publishes fixed firmware or a per-family workaround for CVE-2026-13584.
  • An Update B from CISA with a longer or corrected model list, since Update A already revised it once.
  • A published CVSS vector or exploitability note, which would say how reliable the timing condition is.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories