A vulnerability (CVE-2025-2399) in Mitsubishi Electric CNC Series devices allows remote attackers to trigger a denial-of-service condition via an out-of-bounds read. The flaw is exploited by sending specially crafted packets to TCP port 683. Multiple models across several product series are affected, with vendor fixes available for most.
Mitsubishi Electric
3 posts
Mitsubishi Electric CNC Series (Update A) (CVE-2025-2399) Mitsubishi Electric Multiple FA Products (Update D) (CVE-2025-3511) CVE-2025-3511 is a high-severity (CVSS 7.5) denial-of-service vulnerability in the Ethernet function of over 50 Mitsubishi Electric FA product models. A remote, unauthenticated attacker can send a specially crafted UDP packet to cause a DoS condition, timeout error, or communication delay. Most affected products require a system reset for recovery. Firmware updates are available for all affected products.
Cyber Centre Daily Advisory Digest — 2026-06-19 (1 advisories) The Canadian Centre for Cyber Security issued an advisory regarding multiple Denial-of-Service (DoS) vulnerabilities affecting Mitsubishi Electric MELSEC iQ-F Series EtherNet/IP and Ethernet modules. Organizations utilizing these industrial control systems should review the vendor advisories and apply the recommended updates to prevent potential operational disruptions.