The Industrial Timing Protocol That Could Let Hackers Stop a Robotic Arm Mid-Grip
Researchers found that a family of protocols keeping factory machines in sync has a fundamental weakness. Exploiting it, they could start and stop robots, mess with factory clocks, and touch every device on the network.

Key points
- Researchers at Nozomi Networks demonstrated live attacks against CC-Link IE TSN, an industrial timing protocol used widely in factory automation, at Black Hat USA in August 2025.
- The attack chain lets a hacker inject fake commands into a factory network and control physical equipment, including robotic arms.
- Separate flaws in Phoenix Contact TSN network switches gave researchers the entry point they needed; a firmware patch is now available.
- CISA published an industrial control systems advisory on July 30, 2026, flagging the core protocol vulnerability.
- Until a long-term cryptographic fix is ready, the strongest available defence is keeping TSN networks physically and logically separated from everything else.
Factory floors run on split-second timing. A robotic arm gripping a car part, a safety button triggering an emergency stop, a conveyor belt slowing for a barcode scan: all of it depends on industrial computers exchanging messages in fractions of a millisecond. Miss the window and machines stop or worse.
A family of timing protocols called Time-Sensitive Networking, or TSN, was built specifically to keep that timing reliable. Think of TSN as a traffic warden inside the factory's data cables, making sure the most critical messages always get through first. But researchers at Nozomi Networks, a security firm acquired by Mitsubishi Electric for roughly one billion dollars, found that this traffic warden can be fooled.
How did the attack actually work?
The researchers focused on CC-Link IE TSN, a standard developed by Mitsubishi Electric that is widely installed in manufacturing plants. At a recorded session at Black Hat USA, Nozomi senior security researcher Luca Cremona showed how the protocol's design lets an attacker slip fake instructions into the message stream at precisely the right moment so factory equipment treats them as legitimate.
Cremona noticed the protocol's timing sequences behaved similarly to a known-vulnerable energy protocol called GOOSE. He tried the same attack techniques. They worked.
Once inside, the team could start and stop robotic arms, force grippers to open and drop whatever they were holding, or quietly nudge the factory's internal clocks. That clock-tampering angle is the insidious one. A tiny drift, invisible at first, compounds until processes fall out of sync, and by then tracing it back to a deliberate intrusion is genuinely hard. "You can basically inject some small drift to the clock that's hard to see or detect," Cremona told Dark Reading, "but after an amount of time you will see the effect."
How did the hackers get close enough to try this?
They needed a way onto the TSN network itself, which is normally isolated. That entry came from Phoenix Contact TSN network switches, the physical devices that route factory traffic. The team found previously unknown flaws in the switches' remote management interfaces, the web-based control panels engineers use to configure the hardware. Our August ICS Patch Tuesday roundup from 12 August 2026 covered Phoenix Contact fixes in that same update cycle, which makes the patch hygiene argument here harder to ignore.
The failure mode is familiar: a management interface reachable from a broader network, or accessible through a single tampered device nearby, becomes the door into an otherwise locked room.
Phoenix Contact has released a firmware update that closes those management interface flaws. CISA's July 30 advisory covers the underlying protocol weakness.
| Item | Detail |
|---|---|
| Protocol targeted | CC-Link IE TSN |
| Switch hardware | Phoenix Contact TSN switches |
| CISA advisory date | July 30, 2026 |
| Patch status | Firmware patch available for switch flaws |
| Long-term protocol fix | In development; cryptographic protections being tested |
Should plant operators be worried right now?
Yes, with context. An attacker needs network access first, which isn't trivial. Network segmentation, keeping TSN networks completely separated from office IT and the internet, remains the strongest available defence while a deeper cryptographic fix is developed. Cremona's team is working with Mitsubishi Electric on adding encryption to the protocol itself, though squeezing cryptography into a system that must operate in under one microsecond is a genuine engineering problem.
Apply the Phoenix Contact firmware patch now, and audit whether your TSN switch management interfaces are reachable from anywhere they shouldn't be. The broader lesson from this research is that CC-Link IE TSN already has optional cryptographic protection for user data, but its gaps at Layer 2, the part of the network stack that handles raw device-to-device framing, gave attackers an easier path. That's where the long-term fix needs to land.
Regular OT firmware updates are unglamorous. They're also what keeps attack chains like this one from completing.



