← Back to home
ICSA-25-205-01  ·  Published 2026-01-29  ·  View on CISA ICS-CERT ↗

Mitsubishi Electric CNC Series (Update B)

CVSS 7.0 HIGH

Risk Summary

Successful exploitation of this vulnerability could allow a local attacker to execute malicious code by getting setup-launcher to load a malicious DLL.

CVEs (1)

Remediations

  • Please download and install the fixed version from the Mitsubishi Electric download site: NC Trainer2: "AC" or later https://www.mitsubishielectric.com/fa/download/index.html.
  • Please download and install the fixed version from the Mitsubishi Electric download site: NC Trainer2 plus: "AC" or later https://www.mitsubishielectric.com/fa/download/index.html.
  • Please download and install the fixed version from the Mitsubishi Electric download site: Mitsubishi Electric Numerical Control Device Communication Software (FCSB1224): "A9" or later https://www.mitsubishielectric.com/fa/download/index.html.
  • Please download and install the fixed version from the Mitsubishi Electric download site: NC Virtual Simulator: "A5" or later https://www.mitsubishielectric.com/fa/download/index.html.
  • Please note that there are no plans to release fixed versions for the following products: NC Designer, NC Analyzer, NC Monitor, NC Trainer, NC Trainer plus, NC Visualizer, Remote Monitor Tool, MS Configurator
  • Restrict physical access to the computer using the product.
  • Install an antivirus software in the computer using the affected product.
  • Do not open untrusted files or click untrusted links.
  • Do not run setup-launchers obtained from sources other than our branches, distributors or the Mitsubishi Electric FA website.
  • Before running the setup-launcher, make sure that no DLL exists in the folder containing the setup-launcher executable file (the name varies depending on the product) for the product.
  • For more information, see Mitsubishi Electric 2025-008 https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-008_en.pdf.

Affected Vendors

Mitsubishi Electric

Affected Products (19)

Mitsubishi Electric · NC Designer2 vers:all/*
Mitsubishi Electric · NC Designer vers:all/*
Mitsubishi Electric · NC Configurator2 vers:all/*
Mitsubishi Electric · NC Analyzer2 vers:all/*
Mitsubishi Electric · NC Analyzer vers:all/*
Mitsubishi Electric · NC Explorer vers:all/*
Mitsubishi Electric · NC Monitor2 vers:all/*
Mitsubishi Electric · NC Monitor vers:all/*
Mitsubishi Electric · NC Trainer2 <="AB"
Mitsubishi Electric · NC Trainer2 plus <="AB"
Mitsubishi Electric · NC Trainer vers:all/*
Mitsubishi Electric · NC Trainer plus vers:all/*
Mitsubishi Electric · NC Visualizer vers:all/*
Mitsubishi Electric · Remote Monitor Tool vers:all/*
Mitsubishi Electric · MS Configurator vers:all/*
Mitsubishi Electric · Mitsubishi Electric Numerical Control Device Communication Software (FCSB1224) <="A8"
Mitsubishi Electric · Mitsubishi Electric CNC communication software runtime library M70LC vers:all/*
Mitsubishi Electric · Mitsubishi Electric CNC communication software runtime library M730LC vers:all/*
Mitsubishi Electric · NC Virtual Simulator <="A4"

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more