Skip to content
Threat Feed
low advisory

Denial of Service Vulnerability in Mitsubishi Electric FA Products

A vulnerability in the Ethernet function of multiple Mitsubishi Electric factory automation products allows remote attackers to trigger a denial-of-service condition via specially crafted UDP packets.

CVE search metadata

CVE search record: CVE-2025-3511. Severity: high. CVSS: 7.5. EPSS: 0.88%. KEV: no. Product: CC-Link IE TSN Remote I/O module (<=09), CC-Link IE TSN Analog-Digital Converter module (<=07), CC-Link IE TSN Digital-Analog Converter module (<=07), CC-Link IE TSN FPGA module (01), CC-Link IE TSN Remote Station Communication LSI CP620 (<=1.08J), MELSEC iQ-R Series CC-Link IE TSN Master/Local Module (<=26), MELSEC iQ-R Series Ethernet Interface Module (<=85), CC-Link IE TSN master/local Station Communication LSI CP610 (<=05), MELSEC iQ-F Series FX5 CC-Link IE TSN Master/Local Module (<=1.020), MELSEC iQ-F Series FX5 Ethernet Module (<=1.200), MELSEC iQ-F Series FX5-ENET/IP Ethernet Module (<=1.106), MELSEC iQ-R Series CPU module (Network Part) (<=85). Brief: Denial of Service Vulnerability in Mitsubishi Electric FA Products. Brief link: https://feed.craftedsignal.io/briefs/2026-08-mitsubishi-fa-dos/

Mitsubishi Electric has disclosed a high-severity vulnerability (CVE-2025-3511) affecting a wide array of Factory Automation (FA) products, including CC-Link IE TSN modules, MELSEC iQ-R series, and MELSEC iQ-F series controllers. The issue stems from Improper Validation of Specified Quantity in Input (CWE-1284) within the devices' Ethernet communication stack. By sending a specially crafted UDP packet to an affected device, a remote, unauthenticated attacker can induce a denial-of-service (DoS) condition, communication timeouts, or significant latency. Depending on the specific product, recovery requires a system reset or the resumption of valid UDP traffic. Given the deployment of these industrial control components within the critical manufacturing sector, this vulnerability poses a risk to operational availability and process continuity. Defenders should identify vulnerable assets within their OT networks and apply vendor-supplied firmware updates where available.

Impact

The vulnerability impacts industrial control system infrastructure globally within the critical manufacturing sector. Successful exploitation results in a loss of network communication for critical I/O modules, CPUs, and interface modules. In many cases, a hardware reset is required to restore normal operations, which could lead to unplanned downtime and disruption of manufacturing processes.

Recommendation

  • Identify all affected Mitsubishi Electric FA hardware using the provided product list and ensure internal inventory reflects the specified vulnerable firmware versions.
  • Implement network segmentation to isolate industrial Ethernet traffic, restricting access to these devices from untrusted network segments.
  • Monitor for anomalous UDP traffic patterns originating from unauthorized sources directed toward industrial Ethernet interfaces.
  • Prioritize firmware updates as provided by Mitsubishi Electric to address CVE-2025-3511 across the entire affected product line.

Immediate actions

Inventory OT assets and identify affected Mitsubishi Electric modules.

OT Security 72h

Mitigations

Isolate vulnerable controllers behind firewall/segmentation.

immediate Network Operations

CVE-2025-3511