Independent perspective. Actionable security.Know what matters · Reduce exposure

Vulnerability Assurance / Intelligence

Mitsubishi Electric FA Products UDP Denial-of-Service

Source context: this article examines information published by the source on August 27, 2026. This site’s publication date is shown separately. Check the latest vendor guidance before acting.

What the vulnerability is

CVE-2025-3511 is a vulnerability resulting from Improper Validation of Specified Quantity in Input (CWE-1284) within the Ethernet function of several Mitsubishi Electric FA products. A remote attacker could send specially crafted UDP packets to trigger various availability impacts depending on the affected hardware:

  • Denial-of-Service (DoS): Affects MELSEC iQ-R Series CC-Link IE TSN Master/Local modules, MELSEC iQ-R Series Ethernet Interface modules, and certain CPU network parts. In these cases, a system reset is required for recovery.
  • Conditional DoS: For CC-Link IE TSN Remote I/O, Analog-Digital Converter, Digital-Analog Converter, FPGA modules, and specific Communication LSIs, a DoS condition may occur if the device does not receive a valid UDP packet within three seconds.
  • Communication Issues: On MELSEC iQ-F Series FX5 Ethernet and FX5-ENET/IP modules, this can cause communication delays in Simple CPU communication or timeout errors in CC-Link IEF Basic communication. While timeouts occur, communication may restore once valid UDP packets are received.

Exposure and applicability

This vulnerability affects a wide range of industrial networking and control hardware. Applicability is determined by the specific module and firmware version:

  • CC-Link IE TSN Remote I/O modules: Versions $\le 09$.
  • CC-Link IE TSN Analog-Digital/Digital-Analog Converter modules: Versions $\le 07$.
  • CC-Link IE TSN FPGA modules: Version $01$.
  • Communication LSIs (CP620 and CP610): CP620 versions $\le 1.08J$; CP610 versions $\le 05$.
  • MELSEC iQ-R Series: RJ71GN11-T2 ($\le 26$), RJ71GN11-EIP ($\le 10$), RJ71GN11-SX ($\le 05$), and Ethernet Interface Module RJ71EN71 ($\le 85$). CPU modules (R04, R08, R16, R32, R120 ENCPU) network parts $\le 85$.
  • MELSEC iQ-F Series: FX5-CCLGN-MS ($\le 1.020$), FX5-ENET ($\le 1.200$), and FX5-ENET/IP ($\le 1.106$).

Remediation priorities

Our analysis suggests prioritizing remediation based on the recovery requirement; devices requiring a full system reset to recover from DoS present a higher operational risk than those that restore communication upon receiving valid packets.

Corrective Actions:
* Firmware Updates: Deploy fixed versions as specified by the vendor (e.g., v10+ for Remote I/O, v86+ for iQ-R CPU network parts and RJ71EN71, v08+ for Converter modules).
* Network Isolation: For systems where immediate patching is not feasible, restrict access to the affected devices using firewalls or by placing them within a dedicated LAN to block untrusted hosts.
* Access Control: Implement VPNs for required internet access and restrict physical access to the hardware and connected LANs.

How to validate remediation

Verification should move beyond simple version checks to ensure exposure is reduced:

  1. Firmware Verification: Confirm that the installed firmware matches or exceeds the fixed versions (e.g., ensuring an iQ-R CPU network part is at v86 or later).
  2. Network Path Analysis: For those relying on mitigations, verify via firewall logs or access control lists (ACLs) that UDP traffic to the affected modules is restricted to authorized management stations and known peers.
  3. Connectivity Baseline: Establish a baseline of normal communication timing for FX5 Ethernet modules to identify if unexpected delays occur, though this does not prove the absence of the vulnerability.

Limits and open questions

Updating firmware reduces the likelihood of exploitation but may not eliminate all residual risks associated with UDP-based attacks. While VPNs are recommended for remote access, they introduce their own potential vulnerabilities and must be maintained independently. It remains unclear if there are specific UDP packet signatures that can be used by Intrusion Detection Systems (IDS) to identify exploitation attempts before a DoS condition occurs.

Source and editorial note

Mitsubishi Electric Multiple FA Products (Update D) · Source date: August 27, 2026 · Retrieved August 31, 2026.

Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.

Request a Vulnerability Assessment

Turn security intelligence into action.

Discuss your exposure, priorities, and the evidence needed to validate the outcome.

Request a security assessment ↗

Turn security intelligence into action.

Understand exposure, prioritize the response, and define evidence for the outcome.

Request a Security Assessment