Source context: this article examines information published by the source on August 27, 2026. This site’s publication date is shown separately. Check the latest vendor guidance before acting.
What the vulnerability is
CVE-2025-2399 is an improper validation of specified index, position, or offset (CWE-1285) within the Mitsubishi Electric CNC Series. A remote attacker can exploit this by sending specially crafted packets to TCP port 683, triggering an out-of-bounds read. The primary impact of a successful exploit is a denial-of-service (DoS) condition on the affected hardware.
Exposure and applicability
This vulnerability affects multiple product lines across different version ranges. Infrastructure owners should identify assets based on the following criteria:
- M800VW, M800VS, M80V, and M80VW (BND-2051W000 through BND-2054W000): Versions up to and including BB.
- M800W, M800S, M80, M80W, and E80 (BND-2005W000 through BND-2009W000): Versions up to and including FM.
- C80 (BND-2036W000): All versions are affected.
- M750VW, M730VW, M720VW, M750VS, M730VS, M720VS, M70V, and E70: Versions up to and including LJ.
Remediation priorities
Our analysis suggests prioritizing remediation based on the asset’s network exposure. Because the attack vector is remote via TCP port 683, assets accessible from untrusted networks represent the highest risk.
Primary Corrective Action: Firmware Updates
Updating to the following versions or later is the supported method for reducing exposure:
* BC or later for M800VW, M800VS, M80V, and M80VW.
* FN or later for M800W, M800S, M80, M80W, and E80.
* LK or later for M750VW, M730VW, M720VW, M750VS, M730VS, M720VS, M70V, and E70.
Compensating Controls
For environments where immediate patching is not feasible, the following controls could reduce the likelihood of exploitation:
* Network Isolation: Implementing firewalls or VPNs to block unauthorized access to TCP port 683.
* IP Filtering: Utilizing built-in IP filter functions available for M800V/M80V and M800/M80/E80 series to restrict traffic to known, trusted hosts.
* Physical Security: Restricting physical access to the CNC hardware and connected network infrastructure.
* Endpoint Protection: Installing anti-virus software on PCs that maintain connectivity with the affected products.
How to validate remediation
To ensure exposure has been reduced, defenders should move beyond simple version checks. We recommend the following validation steps:
1. Patch Verification: Confirm the successful application of the fixed firmware versions (BC, FN, or LK) through a Mitsubishi Electric representative to ensure the update was applied correctly.
2. Network Validation: For those relying on compensating controls, verify that TCP port 683 is unreachable from untrusted network segments using authorized network scanning tools.
3. Configuration Audit: Review IP filter settings on M800V/M80V and M800/M80/E80 series to confirm only authorized management IPs are permitted.
Limits and open questions
While firmware updates address the underlying vulnerability, residual risk remains if the update process is not verified or if unauthorized access persists via other vectors. Compensating controls such as VPNs and anti-virus software minimize risk but do not remediate the root cause of the out-of-bounds read. It remains unknown if there are alternative entry paths to TCP port 683 that bypass standard IP filters.
Source and editorial note
Mitsubishi Electric CNC Series (Update A) · Source date: August 27, 2026 · Retrieved August 31, 2026.
Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.
Request a Vulnerability Assessment
Turn security intelligence into action.
Discuss your exposure, priorities, and the evidence needed to validate the outcome.
Request a security assessment ↗