{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/melsec-iq-r-series-cpu-module-network-part-85/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2025-3511"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CC-Link IE TSN Remote I/O module (\u003c=09)","CC-Link IE TSN Analog-Digital Converter module (\u003c=07)","CC-Link IE TSN Digital-Analog Converter module (\u003c=07)","CC-Link IE TSN FPGA module (01)","CC-Link IE TSN Remote Station Communication LSI CP620 (\u003c=1.08J)","MELSEC iQ-R Series CC-Link IE TSN Master/Local Module (\u003c=26)","MELSEC iQ-R Series Ethernet Interface Module (\u003c=85)","CC-Link IE TSN master/local Station Communication LSI CP610 (\u003c=05)","MELSEC iQ-F Series FX5 CC-Link IE TSN Master/Local Module (\u003c=1.020)","MELSEC iQ-F Series FX5 Ethernet Module (\u003c=1.200)","MELSEC iQ-F Series FX5-ENET/IP Ethernet Module (\u003c=1.106)","MELSEC iQ-R Series CPU module (Network Part) (\u003c=85)"],"_cs_severities":["low"],"_cs_tags":["industrial-control-systems","denial-of-service","cve-2025-3511"],"_cs_type":"advisory","_cs_vendors":["Mitsubishi Electric"],"content_html":"\u003cp\u003eMitsubishi Electric has disclosed a high-severity vulnerability (CVE-2025-3511) affecting a wide array of Factory Automation (FA) products, including CC-Link IE TSN modules, MELSEC iQ-R series, and MELSEC iQ-F series controllers. The issue stems from Improper Validation of Specified Quantity in Input (CWE-1284) within the devices' Ethernet communication stack. By sending a specially crafted UDP packet to an affected device, a remote, unauthenticated attacker can induce a denial-of-service (DoS) condition, communication timeouts, or significant latency. Depending on the specific product, recovery requires a system reset or the resumption of valid UDP traffic. Given the deployment of these industrial control components within the critical manufacturing sector, this vulnerability poses a risk to operational availability and process continuity. Defenders should identify vulnerable assets within their OT networks and apply vendor-supplied firmware updates where available.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability impacts industrial control system infrastructure globally within the critical manufacturing sector. Successful exploitation results in a loss of network communication for critical I/O modules, CPUs, and interface modules. In many cases, a hardware reset is required to restore normal operations, which could lead to unplanned downtime and disruption of manufacturing processes.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all affected Mitsubishi Electric FA hardware using the provided product list and ensure internal inventory reflects the specified vulnerable firmware versions.\u003c/li\u003e\n\u003cli\u003eImplement network segmentation to isolate industrial Ethernet traffic, restricting access to these devices from untrusted network segments.\u003c/li\u003e\n\u003cli\u003eMonitor for anomalous UDP traffic patterns originating from unauthorized sources directed toward industrial Ethernet interfaces.\u003c/li\u003e\n\u003cli\u003ePrioritize firmware updates as provided by Mitsubishi Electric to address CVE-2025-3511 across the entire affected product line.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-27T16:05:55Z","date_published":"2026-08-27T16:05:55Z","id":"https://feed.craftedsignal.io/briefs/2026-08-mitsubishi-fa-dos/","summary":"A vulnerability in the Ethernet function of multiple Mitsubishi Electric factory automation products allows remote attackers to trigger a denial-of-service condition via specially crafted UDP packets.","title":"Denial of Service Vulnerability in Mitsubishi Electric FA Products","url":"https://feed.craftedsignal.io/briefs/2026-08-mitsubishi-fa-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - MELSEC IQ-R Series CPU Module (Network Part) (\u003c=85)","version":"https://jsonfeed.org/version/1.1"}