Post

Mitsubishi Electric GX Works3 and Motion Control Settings Vulnerability

Mitsubishi Electric GX Works3 and Motion Control Settings Vulnerability

Mitsubishi Electric GX Works3 and Motion Control Settings Vulnerability

🚨 Attention: A critical vulnerability has been identified in Mitsubishi Electric GX Works3 and Motion Control Settings. This vulnerability, known as CVE-2026-15688, allows local attackers to authenticate with an invalid block password, potentially leading to unauthorized access and manipulation of control programs.

Affected Products

The following versions are affected:

  • Mitsubishi Electric GX Works3: all versions
  • Mitsubishi Electric Motion Control Settings: all versions packaged with GX Works3

For customers using GX Works3:

  • Download version 1.096A or later from here.
  • Set the security version for projects to “2”.

For customers using Motion Control Settings:

  • Download version 1.070Y or later from here.
  • Set the security version for projects to “2”.

Additional Recommendations

To minimize the risk of exploitation:

  • Use the affected product within a LAN and block remote logins from untrusted networks.
  • Implement firewalls and VPNs to prevent unauthorized access.
  • Restrict physical access to computers running the affected software.

For more information, refer to the Mitsubishi Electric security advisory.

For the complete article, visit: CISA.

This post is licensed under CC BY 4.0 by the author.