A vulnerability (CVE-2025-2399) in Mitsubishi Electric CNC Series devices allows remote attackers to trigger a denial-of-service condition via an out-of-bounds read. The flaw is exploited by sending specially crafted packets to TCP port 683. Multiple models across several product series are affected, with vendor fixes available for most.
cnc
1 post
Mitsubishi Electric CNC Series (Update A) (CVE-2025-2399)