ICSA-25-205-01
·
Published 2026-01-29
·
View on CISA ICS-CERT ↗
Mitsubishi Electric CNC Series (Update B)
CVSS 7.0
HIGH
Risk Summary
Successful exploitation of this vulnerability could allow a local attacker to execute malicious code by getting setup-launcher to load a malicious DLL.
CVEs (1)
Remediations
- Please download and install the fixed version from the Mitsubishi Electric download site: NC Trainer2: "AC" or later https://www.mitsubishielectric.com/fa/download/index.html.
- Please download and install the fixed version from the Mitsubishi Electric download site: NC Trainer2 plus: "AC" or later https://www.mitsubishielectric.com/fa/download/index.html.
- Please download and install the fixed version from the Mitsubishi Electric download site: Mitsubishi Electric Numerical Control Device Communication Software (FCSB1224): "A9" or later https://www.mitsubishielectric.com/fa/download/index.html.
- Please download and install the fixed version from the Mitsubishi Electric download site: NC Virtual Simulator: "A5" or later https://www.mitsubishielectric.com/fa/download/index.html.
- Please note that there are no plans to release fixed versions for the following products: NC Designer, NC Analyzer, NC Monitor, NC Trainer, NC Trainer plus, NC Visualizer, Remote Monitor Tool, MS Configurator
- Restrict physical access to the computer using the product.
- Install an antivirus software in the computer using the affected product.
- Do not open untrusted files or click untrusted links.
- Do not run setup-launchers obtained from sources other than our branches, distributors or the Mitsubishi Electric FA website.
- Before running the setup-launcher, make sure that no DLL exists in the folder containing the setup-launcher executable file (the name varies depending on the product) for the product.
- For more information, see Mitsubishi Electric 2025-008 https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-008_en.pdf.
Affected Vendors
Mitsubishi Electric
Affected Products (19)
Mitsubishi Electric
·
NC Designer2
vers:all/*
Mitsubishi Electric
·
NC Designer
vers:all/*
Mitsubishi Electric
·
NC Configurator2
vers:all/*
Mitsubishi Electric
·
NC Analyzer2
vers:all/*
Mitsubishi Electric
·
NC Analyzer
vers:all/*
Mitsubishi Electric
·
NC Explorer
vers:all/*
Mitsubishi Electric
·
NC Monitor2
vers:all/*
Mitsubishi Electric
·
NC Monitor
vers:all/*
Mitsubishi Electric
·
NC Trainer2
<="AB"
Mitsubishi Electric
·
NC Trainer2 plus
<="AB"
Mitsubishi Electric
·
NC Trainer
vers:all/*
Mitsubishi Electric
·
NC Trainer plus
vers:all/*
Mitsubishi Electric
·
NC Visualizer
vers:all/*
Mitsubishi Electric
·
Remote Monitor Tool
vers:all/*
Mitsubishi Electric
·
MS Configurator
vers:all/*
Mitsubishi Electric
·
Mitsubishi Electric Numerical Control Device Communication Software (FCSB1224)
<="A8"
Mitsubishi Electric
·
Mitsubishi Electric CNC communication software runtime library M70LC
vers:all/*
Mitsubishi Electric
·
Mitsubishi Electric CNC communication software runtime library M730LC
vers:all/*
Mitsubishi Electric
·
NC Virtual Simulator
<="A4"
Affected Sectors
Critical Manufacturing
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more