Source context: this article examines information published by the source on August 27, 2026. This site’s publication date is shown separately. Check the latest vendor guidance before acting.
What the vulnerability is
A vulnerability identified as CVE-2025-3511 (CWE-1284: Improper Validation of Specified Quantity in Input) exists within the Ethernet functions of several Mitsubishi Electric Factory Automation (FA) products. A remote attacker could send a specially crafted UDP packet to an affected device, potentially resulting in a denial-of-service (DoS) condition, timeout errors, or communication delays.
In cases where a DoS occurs, the source indicates that a full system reset of the product is required for recovery. For certain modules, such as those experiencing timeout errors in CC-Link IEF Basic communication, connectivity may be restored once the device begins receiving valid UDP packets again.
Exposure and applicability
This vulnerability affects a broad range of industrial automation hardware across several series:
- MELSEC iQ-R Series: Affected components include CPU modules (R04ENCPU, R08ENCPU, R16ENCPU, R32ENCPU, and R120ENCPU network parts), the RJ71EN71 Ethernet Interface Module, and CC-Link IE TSN Master/Local Modules (RJ71GN11-T2, RJ71GN11-EIP, and RJ71GN11-SX).
- MELSEC iQ-F Series: Affected components include FX5 Ethernet Modules (FX5-ENET and FX5-ENET/IP) and the FX5-CCLGN-MS CC-Link IE TSN Master/Local Module.
- CC-Link IE TSN Components: A wide array of Remote I/O modules, Analog-Digital Converter modules (NZ2GN2S-60AD4, NZ2GN2B-60AD4), Digital-Analog Converter modules (NZ2GN2S-60DA4, NZ2GN2B-60DA4), FPGA modules, and various Station Communication LSIs (CP610 and CP620).
Asset owners should verify specific firmware versions against the vendor’s advisory to determine if their hardware falls within the affected ranges (e.g., iQ-R CPU network parts version $\le 85$ or Remote I/O modules $\le 09$).
Remediation priorities
Our analysis suggests prioritizing remediation based on the criticality of the physical process controlled by the affected asset, as a DoS event would require a manual system reset.
1. Firmware Updates: The primary resolution is to apply fixed firmware versions provided by Mitsubishi Electric. Key updates include:
* iQ-R CPU Network Parts: Version 86 or later.
* Remote I/O Modules: Version 10 or later.
* FX5 Ethernet Modules: Version 1.210 (FX5-ENET) or 1.107 (FX5-ENET/IP).
* Other modules: Refer to the vendor’s specific version requirements for Analog/Digital converters and FPGA modules.
2. Network Segmentation: For environments where immediate patching is not feasible due to operational uptime requirements, we recommend restricting UDP traffic to these devices. Implementing firewalls to block access from untrusted networks and hosts can reduce the attack surface.
3. Access Control: Restricting physical access to the LAN and the hardware itself serves as a baseline defense against unauthorized local network injection of crafted packets.
How to validate remediation
Validation should be conducted through a combination of administrative checks and controlled environment testing:
- Version Verification: Confirm that the installed firmware version matches or exceeds the fixed versions listed in the vendor advisory. Note that a version check confirms the update was applied but does not guarantee the absence of other vulnerabilities.
- Configuration Audit: Review firewall rules to ensure that only authorized engineering workstations and necessary controllers can communicate with the affected UDP ports on these modules.
- Controlled Testing: In a non-production staging environment, verify that the updated firmware maintains expected communication stability under normal operational loads before deploying to live production systems.
Limits and open questions
While firmware updates address the root cause of CVE-2025-3511, they do not eliminate the risk of other undiscovered vulnerabilities in the Ethernet stack. Additionally, while VPNs are suggested as a mitigation for remote access, it is important to recognize that VPNs may possess their own vulnerabilities and must be maintained independently. The source does not provide evidence of active exploitation in the wild; however, the requirement for a system reset following a DoS event presents a significant availability risk for continuous industrial processes.
Source and editorial note
Mitsubishi Electric Multiple FA Products (Update D) · Source date: August 27, 2026 · Retrieved August 31, 2026.
Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.
Request an OT security assessment
Protect the systems your operations depend on.
Discuss your industrial environment, prioritize exposure, and establish evidence that safeguards work.
Request an OT assessment ↗