Executive Summary

Industrial automation vendor Mitsubishi Electric, in coordination with Japan Computer Emergency Response Team (JPCERT/CC) and CISA, has published an urgent cybersecurity advisory addressing a high-severity vulnerability affecting MELSEC iQ-R Series programmable logic controllers (PLCs). Designated CVE-2026-59820, the flaw carries a CVSS v3.1 base score of 8.6 (High) and impacts flagship industrial automation controllers globally.

The MELSEC iQ-R family is widely deployed across precision manufacturing, automotive assembly lines, semiconductor packaging facilities, and food processing plants. The flaw enables an unauthenticated attacker connected to the plant control network to transmit crafted packets that directly modify PLC internal data registers, potentially altering machinery sequencing or triggering physical equipment stoppages.

Root Cause Analysis: Unauthenticated SLMP Function Code Processing

The vulnerability exists within the handling of the Seamless Message Protocol (SLMP) over Ethernet TCP/UDP port 5007. Under default engineering configurations, the controller accepts SLMP device read and write commands from any connected host without verifying the source IP address against an engineering station whitelist.

Security analysis identified that specific extended command codes (such as Device Block Write 0x1401) bypassed internal passcode protection routines when submitted alongside malformed sub-header flags. An attacker can craft a sequence of SLMP packets to overwrite data registers (D-registers) and link relays (B-relays) that control automated robotic arm speeds, motor interlocks, and safety line stops.

Packet Ingress Trace:
1. Attacker sends UDP frame to PLC Port 5007 with SLMP Command 0x1401
2. Malformed sub-header bypasses engineering passcode check in firmware
3. Controller firmware writes attacker values directly to Data Registers (D100-D150)
4. Active ladder logic executes modified setpoint values
5. Line stops or machinery operates outside calibrated tolerances

Operational Impact on Industrial Production

In manufacturing environments adhering to IEC 62443, industrial PLCs represent the physical execution tier (Level 1). Unauthorized manipulation of MELSEC iQ-R controllers enables adversaries to:

  • Modify robotic weld timing and torque specifications, introducing undetectable structural defects into manufactured components.
  • Trigger emergency fault alarms on HMI panels, halting high-throughput assembly lines and inflicting substantial financial losses.
  • Corrupt PLC non-volatile memory parameters, requiring engineers to re-flash controller programs via USB.

Remediation & Defense-in-Depth Playbook

Mitsubishi Electric has released firmware revisions and recommends asset owners execute the following defense sequence:

  1. Update Controller Firmware: Flash MELSEC iQ-R CPU modules to the latest firmware revision using GX Works3 engineering software.
  2. Enable IP Packet Filter: Configure the built-in IP packet filter in GX Works3 to restrict SLMP communication on port 5007 exclusively to authorized engineering workstations and SCADA servers.
  3. Enforce Level 2/3 Industrial Firewall Rules: Prohibit all routing from enterprise IT networks to manufacturing cell networks, isolating PLC backplanes in dedicated Purdue Model security zones.