World News

Industry news and insights from Europe and around the World

UK News

Latest news and developments in the United Kingdom

Products

Keep up-to-date with the latest new products and technology

Features

General articles, applications and industry analysis

Mitsubishi warns of AC controller vulnerability

JAPAN: Mitsubishi Electric has warned of a vulnerability in some of its multiple air conditioning controllers which could allow an attacker to bypass authentication.

By exploiting the vulnerability. Mitsubishi Electric warns that an attacker could control the air conditioning systems illegally, or disclose information in them. In addition, the attacker could tamper with firmware for the affected products using the disclosed information. 

The vulnerability, which is said to to affect 27 controller models, has been reported to the USA’s cyber defence agency CISA. It has been assigned a CVSS v3.1 base score of 9.8, a critical vulnerability with the highest possible severity. 

The models affected are:
G-50: Ver 3.37 and prior
G-50-W: Ver 3.37 and prior
G-50A: Ver 3.37 and prior
GB-50: Ver 3.37 and prior
GB-50A: Ver 3.37 and prior
GB-24A: Ver 9.12 and prior
G-150AD: Ver 3.21 and prior
AG-150A-A: Ver 3.21 and prior
AG-150A-J: Ver 3.21 and prior
GB-50AD: Ver.3 21 and prior
GB-50ADA-A: Ver 3.21 and prior
GB-50ADA-J: Ver 3.21 and prior
EB-50GU-A: Ver 7.11 and prior
EB-50GU-J: Ver 7.11 and prior
AE-200J: Ver 8.01 and prior
AE-200A: Ver 8.01 and prior
AE-200E: Ver 8.01 and prior
AE-50J: Ver 8.01 and prior
AE-50A: Ver 8.01 and prior
AE-50E: Ver 8.01 and prior
EW-50J: Ver 8.01 and prior
EW-50A: Ver 8.01 and prior
EW-50E: Ver 8.01 and prior
TE-200A: Ver 8.01 and prior
TE-50A: Ver 8.01 and prior
TW-50A: Ver 8.01 and prior
CMS-RMD-J: Ver 1.40 and prior.

To minimise the risk, Mitsubishi Electric advises that users should make sure that the air conditioning system is configured as recommended by Mitsubishi Electric. It also recommends restricting access to an affected air conditioning system from untrusted networks and hosts and  restricting physical access to the system. It also advises using an anti-virus software and update the OS and the web browser to the latest version on the connected computer. 

Further information is contained in this release from Mitsubishi Electric.

Latest News

9th July 2025

IOR invites responses to EN378 revision

UK: The Institute of Refrigeration says it will be developing a coordinated response to the proposed revision of EN378 standard and has urged input from the UK industry.
9th July 2025

Systemair to acquire Indian fan manufacturer

SWEDEN: Systemair AB has signed an agreement to acquire NADI Airtechnics Ltd, a leading Indian manufacturer of industrial fans.
9th July 2025

AIT brings low-charge R290 heat pump to market

GERMANY: The Kasendorf-based manufacturer AIT-Group has launched the first refrigerant-reduced R290 heat pumps based on the scientific work of the Fraunhofer Institute’s LC150 project.
8th July 2025

Work begins on expanding heat pump facility 

DENMARK: Johnson Controls has broken ground on an expansion of its Holme heat pump and chiller facility in Aarhus, Denmark. 
8th July 2025

Nordic Climate acquires Dutch firm Climanova

SWEDEN/NETHERLANDS: The Nordic Climate Group has continued its expansion with the acquisition of Climanova, a company offering cooling, climate control, and heating solutions with bases in the Netherlands and Belgium.
8th July 2025

Eurovent guidance on incomplete deliveries 

BELGIUM: Eurovent has released updated versions of its guidance for manufacturers, distributors, and end-users of refrigerated cabinets.