Mitsubishi Electric CNC Series Out-of-Bounds Read Denial-of-Service (Update A)
First seen Aug 28, 2026 · Updated Aug 28, 2026 · CVSS 5.9
A vulnerability (CVE-2025-2399) in multiple Mitsubishi Electric CNC Series products allows a remote attacker to trigger an out-of-bounds read by sending specially crafted packets to TCP port 683, resulting in a denial-of-service condition. The flaw affects a wide range of M800/M80/E80, M800V/M80V, and M700V/M70V/E70 series controllers used in industrial manufacturing environments. Vendor fixes are available for most affected product lines, with mitigations recommended for systems that cannot be immediately patched.
Technical Analysis
The vulnerability is classified as CWE-1285 (Improper Validation of Specified Index, Position, or Offset in Input) and is remotely exploitable over TCP port 683 without authentication or user interaction (CVSS v3.1: AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H, score 5.9). Successful exploitation causes an out-of-bounds read leading to a denial-of-service condition on the CNC controller, impacting availability of industrial control operations rather than confidentiality or integrity. Affected products span numerous Mitsubishi Electric CNC series firmware versions, with vendor-issued fixed versions (BC, FN, LK, or later) available for most lines. This is a purely OT/industrial control system vulnerability with no direct exposure to IT networks, cloud services, or software supply chains, and there is no plausible impact to AI agent systems, LLM tool use, or RAG pipelines given the isolated nature of CNC controller networking and lack of any AI/agent integration points in the affected products.
Affected Systems
Mitsubishi Electric M800VW (BND-2051W000) <=BB; M800VS (BND-2052W000) <=BB; M80V (BND-2053W000) <=BB; M80VW (BND-2054W000) <=BB; M800W (BND-2005W000) <=FM; M800S (BND-2006W000) <=FM; M80 (BND-2007W000) <=FM; M80W (BND-2008W000) <=FM; E80 (BND-2009W000) <=FM; C80 (BND-2036W000) all versions; M750VW (BND-1015W002) <=LJ; M730VW (BND-1015W000) <=LJ; M720VW (BND-1015W000) <=LJ; M750VS (BND-1012W002) <=LJ; M730VS (BND-1012W000) <=LJ; M720VS (BND-1012W000) <=LJ; M70V (BND-1018W000) <=LJ; E70 (BND-1022W000) <=LJ
Indicators of Compromise
- TCP port 683 (targeted service port for exploitation)
- No file hashes, IPs, or domains published for this vulnerability
Remediation Steps
- 1
Apply vendor firmware updates
Update M800VW/M800VS/M80V/M80VW to version BC or later; M800W/M800S/M80/M80W/E80 to version FN or later; M750VW/M730VW/M720VW/M750VS/M730VS/M720VS/M70V/E70 to version LK or later. Contact Mitsubishi Electric representative for update instructions.
- 2
Restrict network access
Use firewalls or VPNs to prevent unauthorized remote access to affected CNC controllers, and ensure devices are not accessible directly from the internet.
- 3
Network segmentation
Operate affected products within an isolated LAN, blocking access from untrusted networks and hosts via firewall rules.
- 4
Enable IP filtering
Configure the built-in IP Address Filter Setting Function (available on M800V/M80V and M800/M80/E80 series) to restrict which hosts can communicate with the controller.
- 5
Physical access controls
Restrict physical access to the CNC devices and connected network equipment to authorized personnel only.
- 6
Endpoint protection
Install and maintain anti-virus software on PCs and workstations that interact with the affected CNC products.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.