ics-otregulatorNewsThe Broadside2 min read

Mitsubishi CC-Link IE TSN Protocol Flaw Leaves 80-Plus Models Unpatched

Every affected model carries the "all versions" designation and the advisory is silent on patch timing, the vulnerability sits in the protocol itself, not in any single device's firmware.


TL;DR

CISA published ICSA-26-211-07 for CVE-2026-13584, a vulnerability in Mitsubishi Electric's CC-Link IE TSN communication protocol that affects more than 80 models spanning MX Controllers, motion modules, remote I/O blocks, safety-function modules, analog converters, servo drives, inverters, and industrial robot controllers. A network-adjacent attacker can tamper with communication data or cause denial-of-service by sending crafted packets under specific timing conditions. Every affected product is designated "all versions," and the advisory contains no patch availability or mitigation timeline.

CISA's advisory lands at an uncomfortable moment for the defense industrial base. CC-Link IE TSN is Mitsubishi's flagship industrial Ethernet protocol, deployed widely in critical manufacturing environments including defense-contractor production lines. A protocol-level vulnerability (rather than a bug in a single device firmware image) means the attack surface spans the entire product family.

The affected list is unusually comprehensive. It includes MELSEC MX Controllers in both R and F series, every master/local module in the RJ71GN11 and FX5-CCLGN-MS lines, motion modules from the RD78G and FX5-40SSC-G families, dozens of block-type remote I/O modules, safety-function remote modules, analog-digital and digital-analog converters, FPGA modules, MELSERVO-J5 and MELSERVO-JET servo amplifiers, FR-A800/F800/E800 inverters with CC-Link IE TSN connectivity, and CR800-D series robot controllers. If it speaks CC-Link IE TSN, it's on the list.

The "vers:all/*" designation across every affected model is what makes this advisory different from the prior CC-Link IE TSN notices CISA has published. Earlier advisories (ICSA-25-128-03 for CVE-2025-3511 affecting remote I/O modules, ICSA-24-158-03 and ICSA-23-278-03 for managed switches) named specific firmware version ranges with corresponding fixed versions. Those were device-level bugs. This one appears to be in the protocol implementation layer that every CC-Link IE TSN device shares.

Mitsubishi hasn't published a coordinated disclosure timeline or indicated whether firmware updates can address the flaw or whether hardware revisions are required. The advisory's mitigation section repeats standard network-segmentation and access-control recommendations, sensible advice, but not a substitute for a patch when the vulnerable protocol handles real-time control data and safety functions.

For the practitioner on Monday, the immediate task is identifying every CC-Link IE TSN device in the environment. That's harder than it sounds when the affected list includes servo drives, inverter communication modules, and robot controller network cards, devices that don't always appear on the IT asset inventory. Once identified, network segmentation and monitoring for anomalous UDP traffic on CC-Link IE TSN segments are the only available controls until Mitsubishi ships fixes.


Published ·Deep Fathom