# Mitsubishi Electric CC-Link IE TSN Flaw Exposes Industrial Controllers to Network-Level DoS and Data Tampering


## The Threat


CC-Link IE TSN is Mitsubishi Electric's flagship industrial Ethernet protocol — a gigabit, time-sensitive networking standard designed to converge safety, motion, and I/O control traffic onto a single deterministic network. It's the backbone of advanced manufacturing cells, and it's built on the premise that what's on the wire is exactly what was sent. CVE-2026-13584 attacks that premise directly.


An attacker with foothold on the same network segment as affected devices can send specially crafted packets at precise timing windows to tamper with communication data in transit. The result: either a denial-of-service condition that halts the control function, or a subtler failure where the device continues operating — just incorrectly. That second outcome is the more dangerous one. A stopped machine announces itself. A machine running on corrupted process data may not.


The vulnerability covers every version of the affected firmware released to date. There is no "safe" legacy version to fall back to; the flaw is architectural to the protocol implementation across the product family.


## Severity and Impact


| Field | Detail |

|---|---|

| CVE | CVE-2026-13584 |

| CWE | CWE-345 — Insufficient Verification of Data Authenticity |

| CVSS 3.1 Score | 6.5 (Medium) |

| Vector String | AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H |

| Attack Vector | Adjacent Network |

| Attack Complexity | High (timing-dependent) |

| Privileges Required | None |

| User Interaction | None |

| Impact | Integrity (data tampering) + Availability (DoS / incorrect operation) |


The "High" complexity rating reflects the timing requirement — the attacker must synchronize malicious packets to a specific window in the protocol exchange. This is not a script-kiddie drive-by, but it is absolutely within reach of a motivated actor with network access and time to characterize the target environment.


## Affected Products


All versions of the following products are confirmed affected:


MELSEC MX Controller — MX-R Series

  • MXR300-16, MXR300-32, MXR300-64
  • MXR500-128, MXR500-256

  • MELSEC MX Controller — MX-F Series

  • MXF100-8-N32, MXF100-8-P32
  • MXF100-16-N32, MXF100-16-P32

  • Master/Local Modules

  • RJ71GN11-T2, RJ71GN11-SX, RJ71GN11-EIP
  • FX5-CCLGN-MS

  • CC-Link IE TSN Interface Boards

  • NZ81GN11-SX, NZ81GN11-T2

  • Motion Modules

  • RD78G4, RD78G8, RD78G16, RD78G64, RD78GHV, RD78GHW
  • FX5-40SSC-G, FX5-80SSC-G

  • Motion Control Board

  • MR-EM441G

  • Block-Type Remote I/O Modules (all versions)

  • NZ2GN2S1 series: 32D, 32T, 32TE, 32DT, 32DTE
  • NZ2GN2B1 series: 32D, 32T, 32TE, 32DT, 32DTE
  • NZ2GNCF1 series: 32D, 32T
  • NZ2GNCE3 series: 32D, 32DT
  • NZ2GN12A4 series: 16D, 16DE
  • NZ2GN12A2 series: 16T
  • Additional models confirmed in the full advisory

  • The breadth of affected products — spanning controllers, motion modules, interface boards, and distributed I/O — means this touches every layer of a CC-Link IE TSN network topology simultaneously.


    ## Mitigations


    Mitsubishi Electric has not released a patch at time of publication. Until firmware updates are available, the recommended mitigations are network architecture controls:


  • Segment the OT network. Devices running CC-Link IE TSN should be on dedicated VLANs or segments with no direct paths from corporate IT, DMZs, or internet-facing systems. This is baseline ICS hygiene but is the critical control here given the adjacent-network attack vector.
  • Use firewalls and unidirectional gateways at the boundary between the CC-Link IE TSN segment and any other network. Restrict which hosts can reach these devices at the switch level using port-based access control lists where possible.
  • Minimize external access. If remote monitoring of these controllers is required, route it through a hardened jump host or industrial DMZ — never expose CC-Link IE TSN devices directly to VPN tunnels shared with general enterprise traffic.
  • Monitor for anomalous traffic patterns. Timing-based attacks often produce irregular packet burst signatures. If your ICS environment has network monitoring (e.g., Claroty, Dragos, or Nozomi), ensure CC-Link IE TSN traffic is being baselined and alerted on.
  • Contact Mitsubishi Electric FA. Check the vendor's security bulletin page for firmware update availability as patches are released on a per-model schedule. The advisory references the Mitsubishi Electric Product Security Incident Response Team (PSIRT) for coordinated disclosure updates.

  • ## References


  • [ICS-CERT / CISA Advisory — CVE-2026-13584](https://www.cisa.gov/uscert/ics)
  • [Mitsubishi Electric Product Security — PSIRT](https://www.mitsubishielectric.com/en/psirt/)
  • [CC-Link Partner Association — CC-Link IE TSN specification](https://www.cc-link.org/)

  • ---


    ## HackWire Analysis


    The headline number here is the product count — but the more important number is zero: zero safe firmware versions across the entire affected lineup. When a flaw lives in the protocol implementation rather than a discrete feature or configuration, vendors can't quietly push a hotfix to one model. Every affected SKU needs its own validated firmware build, and in industrial environments, firmware updates on production controllers require change control windows, vendor support, and often physical access. That process takes months, not days.


    What makes this particularly pointed is the attack surface CC-Link IE TSN occupies. This is not a legacy fieldbus running in a corner of the plant — it's the network that connects motion controllers to robot arms, synchronized servo systems, and safety-critical I/O in modern smart factories. The "incorrect operation" outcome deserves more attention than the DoS case: a manufacturing cell that receives corrupted motion commands or I/O state doesn't necessarily stop. It may produce defective output, damage tooling, or — in the worst case — create unsafe physical conditions before any alarm fires.


    The adjacent-network requirement will prompt some defenders to check this off as low exposure. That's the wrong read. Flat OT networks remain common, and initial access through an engineering workstation or HMI on the same segment is a documented path in every major ICS threat actor playbook from TRITON onward. The High complexity rating buys defenders some time; it does not buy them comfort. Automotive, semiconductor, and food & beverage manufacturers running MELSEC-based lines should treat this as a trigger to audit their CC-Link IE TSN network segmentation now, before a patch is available.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)