World News

Industry news and insights from Europe and around the World

UK News

Latest news and developments in the United Kingdom

Products

Keep up-to-date with the latest new products and technology

Features

General articles, applications and industry analysis

Mitsubishi warns of AC controller vulnerability

JAPAN: Mitsubishi Electric has warned of a vulnerability in some of its multiple air conditioning controllers which could allow an attacker to bypass authentication.

By exploiting the vulnerability. Mitsubishi Electric warns that an attacker could control the air conditioning systems illegally, or disclose information in them. In addition, the attacker could tamper with firmware for the affected products using the disclosed information. 

The vulnerability, which is said to to affect 27 controller models, has been reported to the USA’s cyber defence agency CISA. It has been assigned a CVSS v3.1 base score of 9.8, a critical vulnerability with the highest possible severity. 

The models affected are:
G-50: Ver 3.37 and prior
G-50-W: Ver 3.37 and prior
G-50A: Ver 3.37 and prior
GB-50: Ver 3.37 and prior
GB-50A: Ver 3.37 and prior
GB-24A: Ver 9.12 and prior
G-150AD: Ver 3.21 and prior
AG-150A-A: Ver 3.21 and prior
AG-150A-J: Ver 3.21 and prior
GB-50AD: Ver.3 21 and prior
GB-50ADA-A: Ver 3.21 and prior
GB-50ADA-J: Ver 3.21 and prior
EB-50GU-A: Ver 7.11 and prior
EB-50GU-J: Ver 7.11 and prior
AE-200J: Ver 8.01 and prior
AE-200A: Ver 8.01 and prior
AE-200E: Ver 8.01 and prior
AE-50J: Ver 8.01 and prior
AE-50A: Ver 8.01 and prior
AE-50E: Ver 8.01 and prior
EW-50J: Ver 8.01 and prior
EW-50A: Ver 8.01 and prior
EW-50E: Ver 8.01 and prior
TE-200A: Ver 8.01 and prior
TE-50A: Ver 8.01 and prior
TW-50A: Ver 8.01 and prior
CMS-RMD-J: Ver 1.40 and prior.

To minimise the risk, Mitsubishi Electric advises that users should make sure that the air conditioning system is configured as recommended by Mitsubishi Electric. It also recommends restricting access to an affected air conditioning system from untrusted networks and hosts and  restricting physical access to the system. It also advises using an anti-virus software and update the OS and the web browser to the latest version on the connected computer. 

Further information is contained in this release from Mitsubishi Electric.

Latest News

21st April 2026

Midea ceiling-mounted inverter AHU

USA: Midea is promoting its inverter-driven Pancake AHU as an easy to install ceiling-mounted ducted solution for a wide range of climates, including cold-weather conditions. 
21st April 2026

Hitachi sells home appliance business to focus on AC

JAPAN: Hitachi has sold its household appliance interests to Nojima Corp to concentrate on its air conditioning business.
21st April 2026

Phil Deverick rejoins General

UK: Phil Deverick has rejoined General HVAC Solutions UK as operations supervisor in a number of new appointments to the former Fujitsu business.
21st April 2026

UK moves to cut electricity price link to gas

UK: The UK government has taken a step towards breaking the link between gas and electricity prices in an effort to decarbonise the grid.
20th April 2026

Expansion valve and constant pressure regulator

DENMARK: AXV is Danfoss’ new mechanical pressure regulator, developed for both hot gas bypass and liquid expansion applications.
19th April 2026

Carter Thermal to host IOR Talk and Tour 

UK: The Institute of Refrigeration will hold its first-ever in-person Talk & Tour at Carter Thermal Industries next month.