highOther

Mitsubishi Electric Multiple FA Products UDP Packet Denial-of-Service Vulnerability (Update D)

First seen Aug 29, 2026 · Updated Aug 29, 2026 · CVSS 7.5

ICSOTdenial-of-serviceCC-LinkMELSECcritical-manufacturingMitsubishi-ElectricCVE-2025-3511

Multiple Mitsubishi Electric FA products, including CC-Link IE TSN modules and MELSEC iQ-R/iQ-F series Ethernet and CPU modules, contain a denial-of-service vulnerability (CVE-2025-3511) in their Ethernet function. A remote attacker can send a specially crafted UDP packet to cause a DoS condition, communication delay, or timeout error, requiring a system reset for recovery in most cases.

Technical Analysis

CVE-2025-3511 stems from Improper Validation of Specified Quantity in Input (CWE-1284) in the Ethernet handling logic of numerous Mitsubishi Electric FA products, where failure to receive a valid UDP packet within 3 seconds triggers a fault condition. Exploitation requires only network access and no authentication or user interaction (CVSS 3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, score 7.5), allowing a remote attacker to crash affected CC-Link IE TSN Remote I/O modules, MELSEC iQ-R CPU network parts, and MELSEC iQ-F Ethernet modules, necessitating a physical/system reset to restore operation. On FX5-ENET and FX5-ENET/IP modules, the flaw instead causes communication delays or timeout errors in Simple CPU and CC-Link IEF Basic communication, which self-recover once valid traffic resumes. This is a pure availability-impacting industrial control system flaw with no confidentiality or integrity impact, affecting critical manufacturing OT environments worldwide. While this is an OT/ICS-specific vulnerability with no direct AI agent code-execution or credential-theft vector, organizations running AI-driven industrial automation, predictive maintenance agents, or agentic SCADA/PLC monitoring tools that rely on continuous connectivity to these Mitsubishi modules could experience agent pipeline disruption or false-positive anomaly triggers if the DoS interrupts telemetry feeds the agents depend on.

Affected Systems

Mitsubishi Electric CC-Link IE TSN Remote I/O modules (NZ2GN2S1/NZ2GN2B1/NZ2GNCF1/NZ2GNCE3/NZ2GN12A series, various firmware <=09 or <=07); CC-Link IE TSN FPGA modules NZ2GN2S-D41P01/D41D01/D41PD02 (v01); CC-Link IE TSN Remote Station Communication LSI CP620 NZ2GACP620-300/-60 (<=1.08J); MELSEC iQ-R Series CC-Link IE TSN Master/Local Modules RJ71GN11-T2 (<=26), RJ71GN11-EIP (<=10), RJ71GN11-SX (<=05); MELSEC iQ-R Ethernet Interface Module RJ71EN71 (<=85); CC-Link IE TSN master/local Station Communication LSI CP610 NZ2GACP610-60/NZ2KT-NPETNG51 (<=05); MELSEC iQ-F Series FX5-CCLGN-MS (<=1.020), FX5-ENET (<=1.200), FX5-ENET/IP (<=1.106); MELSEC iQ-R CPU modules R04ENCPU/R08ENCPU/R16ENCPU/R32ENCPU/R120ENCPU (Network Part, <=85).

Indicators of Compromise

  • No specific IOCs published; exploitation involves specially crafted UDP packets sent to affected device network interfaces. No known malware samples, hashes, IPs, or domains associated with this vulnerability.

Remediation Steps

  1. 1

    Apply vendor firmware updates

    Update affected products to the fixed firmware/software versions specified by Mitsubishi Electric (e.g., version 10+ for Remote I/O modules, version 86+ for RJ71EN71 and CPU network parts, version 1.09K+ for CP620, version 06+ for CP610, version 1.210+ for FX5-ENET, version 1.107+ for FX5-ENET/IP) via the official download portal.

  2. 2

    Network segmentation

    Isolate control system networks and affected devices behind firewalls, separating them from business/IT networks and blocking access from untrusted networks and hosts.

  3. 3

    Restrict remote access

    Use VPNs for necessary remote access, keeping VPN software updated, and avoid exposing affected devices directly to the internet.

  4. 4

    Restrict physical access

    Limit physical access to affected devices and their LAN to authorized personnel only.

  5. 5

    Endpoint protection

    Install and maintain anti-virus/endpoint protection on PCs that can access the affected products.

  6. 6

    Monitor and report

    Monitor for anomalous UDP traffic targeting these devices and report suspected malicious activity to CISA for tracking.

CVE / Advisory IDs

CVE-2025-3511

Industries Most Exposed

Critical ManufacturingIndustrial AutomationEnergyUtilitiesBuilding Automation

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.