World News

Industry news and insights from Europe and around the World

UK News

Latest news and developments in the United Kingdom

Products

Keep up-to-date with the latest new products and technology

Features

General articles, applications and industry analysis

Mitsubishi warns of AC controller vulnerability

JAPAN: Mitsubishi Electric has warned of a vulnerability in some of its multiple air conditioning controllers which could allow an attacker to bypass authentication.

By exploiting the vulnerability. Mitsubishi Electric warns that an attacker could control the air conditioning systems illegally, or disclose information in them. In addition, the attacker could tamper with firmware for the affected products using the disclosed information. 

The vulnerability, which is said to to affect 27 controller models, has been reported to the USA’s cyber defence agency CISA. It has been assigned a CVSS v3.1 base score of 9.8, a critical vulnerability with the highest possible severity. 

The models affected are:
G-50: Ver 3.37 and prior
G-50-W: Ver 3.37 and prior
G-50A: Ver 3.37 and prior
GB-50: Ver 3.37 and prior
GB-50A: Ver 3.37 and prior
GB-24A: Ver 9.12 and prior
G-150AD: Ver 3.21 and prior
AG-150A-A: Ver 3.21 and prior
AG-150A-J: Ver 3.21 and prior
GB-50AD: Ver.3 21 and prior
GB-50ADA-A: Ver 3.21 and prior
GB-50ADA-J: Ver 3.21 and prior
EB-50GU-A: Ver 7.11 and prior
EB-50GU-J: Ver 7.11 and prior
AE-200J: Ver 8.01 and prior
AE-200A: Ver 8.01 and prior
AE-200E: Ver 8.01 and prior
AE-50J: Ver 8.01 and prior
AE-50A: Ver 8.01 and prior
AE-50E: Ver 8.01 and prior
EW-50J: Ver 8.01 and prior
EW-50A: Ver 8.01 and prior
EW-50E: Ver 8.01 and prior
TE-200A: Ver 8.01 and prior
TE-50A: Ver 8.01 and prior
TW-50A: Ver 8.01 and prior
CMS-RMD-J: Ver 1.40 and prior.

To minimise the risk, Mitsubishi Electric advises that users should make sure that the air conditioning system is configured as recommended by Mitsubishi Electric. It also recommends restricting access to an affected air conditioning system from untrusted networks and hosts and  restricting physical access to the system. It also advises using an anti-virus software and update the OS and the web browser to the latest version on the connected computer. 

Further information is contained in this release from Mitsubishi Electric.

Latest News

23rd July 2026

Carrier acquires intelligent building company 75F

USA: Carrier has acquired 75F, a Minneapolis-based innovator of cloud-native, wireless, AI-enabled building automation systems.
23rd July 2026

Any F-gas delay risks crippling Spanish retailers

SPAIN: The Environmental Investigation Agency (EIA) has warned a Spanish retailers association that moves to delay the phase down of F-gases risk crippling the very retailers they claim to protect.
23rd July 2026

REFCOM registers 10,000th member

UK: F-Gas certification body REFCOM has registered its 10,000th member, as demand surges for heat pumps and other low carbon solutions.
23rd July 2026

Delivering net zero healthcare 

UK: A Panasonic air-source heat pump linked to an hydronic skirting heating system is key to the successful redevelopment of Goodmayes Hospital mental healthcare facility in Ilford, Essex.
23rd July 2026

HPA UK backs push for heat networks

UK: Heat Pump Association UK (HPA UK) has urged the government to provide greater regulatory clarity, targeted funding and stronger policy recognition for heat-pump-driven low-carbon heat networks.
23rd July 2026

Beijer Ref CEO resigns

SWEDEN: Beijer Ref CEO Christopher Norbye has announced that he will step down from his post to pursue “new opportunities" elsewhere.