World News

Industry news and insights from Europe and around the World

UK News

Latest news and developments in the United Kingdom

Products

Keep up-to-date with the latest new products and technology

Features

General articles, applications and industry analysis

Mitsubishi warns of AC controller vulnerability

JAPAN: Mitsubishi Electric has warned of a vulnerability in some of its multiple air conditioning controllers which could allow an attacker to bypass authentication.

By exploiting the vulnerability. Mitsubishi Electric warns that an attacker could control the air conditioning systems illegally, or disclose information in them. In addition, the attacker could tamper with firmware for the affected products using the disclosed information. 

The vulnerability, which is said to to affect 27 controller models, has been reported to the USA’s cyber defence agency CISA. It has been assigned a CVSS v3.1 base score of 9.8, a critical vulnerability with the highest possible severity. 

The models affected are:
G-50: Ver 3.37 and prior
G-50-W: Ver 3.37 and prior
G-50A: Ver 3.37 and prior
GB-50: Ver 3.37 and prior
GB-50A: Ver 3.37 and prior
GB-24A: Ver 9.12 and prior
G-150AD: Ver 3.21 and prior
AG-150A-A: Ver 3.21 and prior
AG-150A-J: Ver 3.21 and prior
GB-50AD: Ver.3 21 and prior
GB-50ADA-A: Ver 3.21 and prior
GB-50ADA-J: Ver 3.21 and prior
EB-50GU-A: Ver 7.11 and prior
EB-50GU-J: Ver 7.11 and prior
AE-200J: Ver 8.01 and prior
AE-200A: Ver 8.01 and prior
AE-200E: Ver 8.01 and prior
AE-50J: Ver 8.01 and prior
AE-50A: Ver 8.01 and prior
AE-50E: Ver 8.01 and prior
EW-50J: Ver 8.01 and prior
EW-50A: Ver 8.01 and prior
EW-50E: Ver 8.01 and prior
TE-200A: Ver 8.01 and prior
TE-50A: Ver 8.01 and prior
TW-50A: Ver 8.01 and prior
CMS-RMD-J: Ver 1.40 and prior.

To minimise the risk, Mitsubishi Electric advises that users should make sure that the air conditioning system is configured as recommended by Mitsubishi Electric. It also recommends restricting access to an affected air conditioning system from untrusted networks and hosts and  restricting physical access to the system. It also advises using an anti-virus software and update the OS and the web browser to the latest version on the connected computer. 

Further information is contained in this release from Mitsubishi Electric.

Latest News

10th November 2025

Beijer Ref opens Glasgow training facility

UK: Lord William Haughey OBE, Chair of City Facilities Management Ltd officially opened the new Glasgow Beijer Ref training facility last week.
10th November 2025

Lowe Rental attracts new investment

UK: Private equity firm MML Keystone has made a majority investment in Lowe Rental Corporation, the Lisburn, Northern Ireland, commercial refrigeration and catering equipment rental company.
9th November 2025

SWEP takes key role in CERN’s CO2 cooling system

SWITZERLAND/FRANCE: Swedish manufacturer SWEP has supplied over a hundred brazed-plate heat exchangers for critical cooling roles at the CERN particle physics laboratory.
9th November 2025

AREA opens membership to “observers”

BELGIUM: AREA, the European umbrella group representing 26 national RACHP contractors associations, is opening its membership to a new category of Observing Partners. 
8th November 2025

Danfoss celebrates Mexico factory expansion

MEXICO: Danfoss has celebrated the opening of an expansion of its Monterrey, Mexico factory, to meet demand for HVAC equipment in the North American and Latin American markets.
8th November 2025

Sanhua and Haier sign co-operation deal

CHINA: Controls company Sanhua has signed a strategic co-operation agreement with appliance manufacturer Haier, extending a partnership which has existed between the two companies for nearly 40 years.