Source context: this article examines information published by the source on August 27, 2026. This site’s publication date is shown separately. Check the latest vendor guidance before acting.
What the vulnerability is
CVE-2025-2399 is an improper validation of specified index, position, or offset in input (CWE-1285). This flaw allows a remote attacker to send specially crafted packets to TCP port 683, which can trigger an out-of-bounds read. The operational consequence of this vulnerability is a denial-of-service (DoS) condition, potentially halting the affected CNC equipment.
Exposure and applicability
This vulnerability affects multiple Mitsubishi Electric CNC Series products across different hardware families. Applicability depends on the specific model and firmware version:
- M800VW, M800VS, M80V, M80VW (BND-2051W000, BND-2052W000, BND-2053W000, BND-2054W000): Versions BB and earlier.
- M800W, M800S, M80, M80W, E80 (BND-2005W000, BND-2006W000, BND-2007W000, BND-2008W000, BND-2009W000): Versions FM and earlier.
- C80 (BND-2036W000): All versions are affected.
- M750VW/VS, M730VW/VS, M720VW/VS, M70V, E70 (BND-1015W002, BND-1015W000, BND-1012W002, BND-1012W000, BND-1018W000, BND-1022W000): Versions LJ and earlier.
Remediation priorities
Our analysis suggests prioritizing remediation based on the accessibility of TCP port 683. Asset owners should first identify affected units via version checks and then pursue the following paths:
Firmware Updates
Updating to a fixed version is the primary method to address the underlying vulnerability. Users must consult a Mitsubishi Electric representative for specific application instructions.
* For M800VW/VS, M80V, and M80VW: Update to version BC or later.
* For M800W/S, M80, M80W, and E80: Update to version FN or later.
* For M750VW/VS, M730VW/VS, M720VW/VS, M70V, and E70: Update to version LK or later.
Network Mitigations
If immediate patching is not feasible, the following controls could reduce the likelihood of exploitation:
* Network Isolation: Restrict affected CNCs to a local area network (LAN) and use firewalls to block access from untrusted hosts or the internet.
* Access Control: Implement IP filter functions where available (specifically for M800V/M80V and M800/M80/E80 series) to limit which devices can communicate with the controller.
* Secure Remote Access: Use a VPN if remote access is required, ensuring the VPN itself is updated.
* Physical Security: Restrict physical access to the CNC hardware and connected networking equipment.
* Endpoint Protection: Install anti-virus software on any PCs that have network access to the affected products.
How to validate remediation
To verify that exposure has been reduced, operators should perform the following checks:
1. Version Verification: Confirm the installed firmware version matches or exceeds the fixed versions (BC, FN, or LK) listed above. Note that a version check alone does not guarantee total security but confirms the patch application.
2. Port Audit: Use authorized network auditing tools to verify that TCP port 683 is not reachable from untrusted network segments or the public internet.
3. Filter Confirmation: For series supporting IP filters, review the configuration to ensure only authorized management workstations are permitted.
Limits and open questions
The source indicates that all versions of the C80 (BND-2036W000) are affected; it is currently unclear if a fix has been developed for this specific model. Additionally, while network mitigations like firewalls and IP filters can limit the attack vector, they do not remove the vulnerability from the device itself. Residual risk remains if an attacker gains access to the trusted LAN or if authorized management PCs are compromised.
Source and editorial note
Mitsubishi Electric CNC Series (Update A) · Source date: August 27, 2026 · Retrieved August 31, 2026.
Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.
Request an OT security assessment
Protect the systems your operations depend on.
Discuss your industrial environment, prioritize exposure, and establish evidence that safeguards work.
Request an OT assessment ↗