Mitsubishi Electric Multiple FA Products (Update D)
VulnView CSAF Summary Successful exploitation of this vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition, a timeout error, or a communication delay by sending a specially crafted UDP packet to the product. The following versions of Mitsubishi Electric Multiple FA Products (Update D) are affected: Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32D <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32T <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32TE <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32DT <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32DTE <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32D <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32T <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32TE <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32DT <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32DTE <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GNCF1-32D <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GNCF1-32T <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GNCE3-32D <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GNCE3-32DT <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A4-16D <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A4-16DE <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A2-16T <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A2-16TE <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A42-16DT <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A42-16DTE <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-16D <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-16T <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-16TE <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-16D <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-16T <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-16TE <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Analog-Digital Converter module NZ2GN2S-60AD4 <=07 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Analog-Digital Converter module NZ2GN2B-60AD4 <=07 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Digital-Analog Converter module NZ2GN2S-60DA4 <=07 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Digital-Analog Converter module NZ2GN2B-60DA4 <=07 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN FPGA module NZ2GN2S-D41P01 01 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN FPGA module NZ2GN2S-D41D01 01 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN FPGA module NZ2GN2S-D41PD02 01 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote Station Communication LSI CP620 with GbE-PHY NZ2GACP620-300 <=1.08J (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote Station Communication LSI CP620 with GbE-PHY NZ2GACP620-60 <=1.08J (CVE-2025-3511) Mitsubishi Electric MELSEC iQ-R Series CC-Link IE TSN Master/Local Module RJ71GN11-T2 <=26 (CVE-2025-3511) Mitsubishi Electric MELSEC iQ-R Series CC-Link IE TSN Master/Local Module RJ71GN11-EIP <=10 (CVE-2025-3511) Mitsubishi Electric MELSEC iQ-R Series CC-Link IE TSN Master/Local Module RJ71GN11-SX <=05 (CVE-2025-3511) Mitsubishi Electric MELSEC iQ-R Series Ethernet Interface Module RJ71EN71 <=85 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN master/local Station Communication LSI CP610 NZ2GACP610-60 <=05 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN master/local Station Communication LSI CP610 NZ2KT-NPETNG51 <=05 (CVE-2025-3511) Mitsubishi Electric MELSEC iQ-F Series FX5 CC-Link IE TSN Master/Local Module FX5-CCLGN-MS <=1.020 (CVE-2025-3511) Mitsubishi Electric MELSEC iQ-F Series FX5 Ethernet Module FX5-ENET <=1.200 (CVE-2025-3511) Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP <=1.106 (CVE-2025-3511) Mitsubishi Electric MELSEC iQ-R Series CPU module R04ENCPU (Network Part) <=85 (CVE-2025-3511) Mitsubishi Electric MELSEC iQ-R Series CPU module R08ENCPU (Network Part) <=85 (CVE-2025-3511) Mitsubishi Electric MELSEC iQ-R Series CPU module R16ENCPU (Network Part) <=85 (CVE-2025-3511) Mitsubishi Electric MELSEC iQ-R Series CPU module R32ENCPU (Network Part) <=85 (CVE-2025-3511) Mitsubishi Electric MELSEC iQ-R Series CPU module R120ENCPU (Network Part) <=85 (CVE-2025-3511) CVSS Vendor Equipment Vulnerabilities v3 7.5 Mitsubishi Electric Mitsubishi Electric Multiple FA Products (Update D) Improper Validation of Specified Quantity in Input Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Japan Vulnerabilities Expand All + CVE-2025-3511 A denial-of-service (DoS) vulnerability due to Improper Validation of Specified Quantity in Input (CWE-1284) exists in the Ethernet function of multiple FA products. This vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition by sending a specially crafted UDP packet if CC-Link IE TSN Remote I/O modules NZ2GN2S1-32D, NZ2GN2S1-32T, NZ2GN2S1-32TE, NZ2GN2S1-32DT, NZ2GN2S1-32DTE, NZ2GN2B1-32D, NZ2GN2B1-32T, NZ2GN2B1-32TE, NZ2GN2B1-32DT, NZ2GN2B1-32DTE, NZ2GNCF1-32D, NZ2GNCF1-32T, NZ2GNCE3-32D, NZ2GNCE3-32DT, NZ2GN12A4-16D, NZ2GN12A4-16DE, NZ2GN12A2-16T, NZ2GN12A2-16TE, NZ2GN12A42-16DT, NZ2GN12A42-16DTE, NZ2GN2S1-16D, NZ2GN2S1-16T, NZ2GN2S1-16TE, NZ2GN2B1-16D, NZ2GN2B1-16T, NZ2GN2B1-16TE, CC-Link IE TSN Analog-Digital Converter modules NZ2GN2S-60AD4, NZ2GN2B-60AD4, CC-Link IE TSN Digital-Analog Converter modules NZ2GN2S-60DA4 and NZ2GN2B-60DA4, CC-Link IE TSN FPGA modules NZ2GN2S-D41P01, NZ2GN2S-D41D01, NZ2GN2S-D41PD02, CC-Link IE TSN Remote Station Communication LSIs CP620 with GbE-PHY NZ2GACP620-300, and NZ2GACP620-60 does not receive a valid UDP packet within 3 seconds. This vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition on MELSEC iQ-R Series CC-Link IE TSN Master/Local Module RJ71GN11-T2, RJ71GN11-EIP, RJ71GN11-SX, MELSEC iQ-R Series Ethernet Interface Module RJ71EN71, CC-Link IE TSN master/local Station Communication LSIs CP610 NZ2GACP610-60, NZ2KT-NPETNG51, MELSEC iQ-F Series FX5 CC-Link IE TSN Master/Local Module FX5-CCLGN-MS, MELSEC iQ-R Series CPU module R04ENCPU (Network part), R08ENCPU (Network part), R16ENCPU (Network part), R32ENCPU (Network part), and R120ENCPU (Network part), by sending a specially crafted UDP packet. Or this vulnerability could allow a remote attacker to cause a communication delay in Simple CPU communication on MELSEC iQ-F Series FX5 Ethernet Module FX5-ENET and FX5-ENET/IP Ethernet Module FX5-ENET/IP, by sending a specially crafted UDP packet. A system reset of the product is required for recovery in all cases above. Additionally, this vulnerability could allow a remote attacker to cause a timeout error in CC-Link IEF Basic communication on MELSEC iQ-F Series FX5 Ethernet Module FX5-ENET and FX5-ENET/IP Ethernet Module FX5-ENET/IP, by sending a specially crafted UDP packet. Even if a timeout error occurs, communication will be restored once the affected product starts receiving valid UDP packets. View CVE Details Affected Products Mitsubishi Electric Multiple FA Products (Update D) Vendor:Mitsubishi Electric Product Version:Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32D: <=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32T: <=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32TE: <=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32DT: <=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32DTE: <=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32D: <=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32T: <=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32TE: <=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32DT: <=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32DTE: <=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GNCF1-32D: <=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GNCF1-32T: <=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GNCE3-32D: <=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GNCE3-32DT: <=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A4-16D: <=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A4-16DE: <=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A2-16T: <=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A2-16TE: <=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A42-16DT: <=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A42-16DTE: <=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-16D: <=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-16T: <=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-16TE: <=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-16D: <=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-16T: <=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-16TE: <=09, Mitsubishi Electric CC-Link IE TSN Analog-Digital Converter module NZ2GN2S-60AD4: <=07, Mitsubishi Electric CC-Link IE TSN Analog-Digital Converter module NZ2GN2B-60AD4: <=07, Mitsubishi Electric CC-Link IE TSN Digital-Analog Converter module NZ2GN2S-60DA4: <=07, Mitsubishi Electric CC-Link IE TSN Digital-Analog Converter module NZ2GN2B-60DA4: <=07, Mitsubishi Electric CC-Link IE TSN FPGA module NZ2GN2S-D41P01: 01, Mitsubishi Electric CC-Link IE TSN FPGA module NZ2GN2S-D41D01: 01, Mitsubishi Electric CC-Link IE TSN FPGA module NZ2GN2S-D41PD02: 01, Mitsubishi Electric CC-Link IE TSN Remote Station Communication LSI CP620 with GbE-PHY NZ2GACP620-300: <=1.08J, Mitsubishi Electric CC-Link IE TSN Remote Station Communication LSI CP620 with GbE-PHY NZ2GACP620-60: <=1.08J, Mitsubishi Electric MELSEC iQ-R Series CC-Link IE TSN Master/Local Module RJ71GN11-T2: <=26, Mitsubishi Electric MELSEC iQ-R Series CC-Link IE TSN Master/Local Module RJ71GN11-EIP: <=10, Mitsubishi Electric MELSEC iQ-R Series CC-Link IE TSN Master/Local Module RJ71GN11-SX: <=05, Mitsubishi Electric MELSEC iQ-R Series Ethernet Interface Module RJ71EN71: <=85, Mitsubishi Electric CC-Link IE TSN master/local Station Communication LSI CP610 NZ2GACP610-60: <=05, Mitsubishi Electric CC-Link IE TSN master/local Station Communication LSI CP610 NZ2KT-NPETNG51: <=05, Mitsubishi Electric MELSEC iQ-F Series FX5 CC-Link IE TSN Master/Local Module FX5-CCLGN-MS: <=1.020, Mitsubishi Electric MELSEC iQ-F Series FX5 Ethernet Module FX5-ENET: <=1.200, Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP: <=1.106, Mitsubishi Electric MELSEC iQ-R Series CPU module R04ENCPU (Network Part): <=85, Mitsubishi Electric MELSEC iQ-R Series CPU module R08ENCPU (Network Part): <=85, Mitsubishi Electric MELSEC iQ-R Series CPU module R16ENCPU (Network Part): <=85, Mitsubishi Electric MELSEC iQ-R Series CPU module R32ENCPU (Network Part): <=85, Mitsubishi Electric MELSEC iQ-R Series CPU module R120ENCPU (Network Part): <=85 Product Status:known_affected Remediations Vendor fixMitsubishi Electric is releasing fixed version 10 or later for CC-Link IE TSN Remote I/O modules NZ2GN2S1-32D, NZ2GN2S1-32T, NZ2GN2S1-32TE, NZ2GN2S1-32DT, NZ2GN2S1-32DTE, NZ2GN2B1-32D, NZ2GN2B1-32T, NZ2GN2B1-32TE, NZ2GN2B1-32DT, NZ2GN2B1-32DTE, NZ2GNCF1-32D, NZ2GNCF1-32T, NZ2GNCE3-32D, NZ2GNCE3-32DT, NZ2GN12A4-16D, NZ2GN12A4-16DE, NZ2GN12A2-16T, NZ2GN12A2-16TE, NZ2GN12A42-16DT, NZ2GN12A42-16DTE, NZ2GN2S1-16D, NZ2GN2S1-16T, NZ2GN2S1-16TE, NZ2GN2B1-16D, NZ2GN2B1-16T, and NZ2GN2B1-16TE. Please download the fixed update file from the link "https://www.mitsubishielectric.com/fa/download/index.html" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-001_en.pdf."https://www.mitsubishielectric.com/fa/download/index.html Vendor fixMitsubishi Electric is releasing fixed version 08 or later for CC-Link IE TSN Analog-Digital Converter modules NZ2GN2S-60AD4 and NZ2GN2B-60AD4. Please download the fixed update file from the link "https://www.mitsubishielectric.com/fa/download/index.html" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-001_en.pdf".https://www.mitsubishielectric.com/fa/download/index.html Vendor fixMitsubishi Electric is releasing fixed version 08 or later for CC-Link IE TSN Digital-Analog Converter modules NZ2GN2S-60DA4 and NZ2GN2B-60DA4. Please download the fixed update file from the link "https://www.mitsubishielectric.com/fa/download/index.html" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-001_en.pdf".https://www.mitsubishielectric.com/fa/download/index.html Vendor fixMitsubishi Electric is releasing fixed version 02 or later for CC-Link IE TSN FPGA modules NZ2GN2S-D41P01, NZ2GN2S-D41D01, and NZ2GN2S-D41PD02. Please download the fixed update file from the link "https://www.mitsubishielectric.com/fa/download/index.html" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-001_en.pdf".https://www.mitsubishielectric.com/fa/download/index.html Vendor fixMitsubishi Electric is releasing fixed version 1.09K or later for CC-Link IE TSN Remote Station Communication LSIs CP620 with GbE-PHY NZ2GACP620-300 or NZ2GACP620-60. Please download the CP620 sample code from the link "https://www.mitsubishielectric.com/fa/download/index.html" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-001_en.pdf".https://www.mitsubishielectric.com/fa/download/index.html Vendor fixMitsubishi Electric is releasing fixed version 28 or later for MELSEC iQ-R Series CC-Link IE TSN Master/Local Module RJ71GN11-T2. Please download the fixed update file from the link "https://www.mitsubishielectric.com/fa/download/index.html" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-001_en.pdf".https://www.mitsubishielectric.com/fa/download/index.html Vendor fixMitsubishi Electric is releasing fixed version 13 or later for MELSEC iQ-R Series CC-Link IE TSN Master/Local Module RJ71GN11-EIP. Please download the fixed update file from the link "https://www.mitsubishielectric.com/fa/download/index.html" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-001_en.pdf".https://www.mitsubishielectric.com/fa/download/index.html Vendor fixMitsubishi Electric is releasing fixed version 07 or later for MELSEC iQ-R Series CC-Link IE TSN Master/Local Module RJ71GN11-SX. Please download the fixed update file from the link "https://www.mitsubishielectric.com/fa/download/index.html" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-001_en.pdf".https://www.mitsubishielectric.com/fa/download/index.html Vendor fixMitsubishi Electric is releasing fixed version 86 or later for MELSEC iQ-R Series Ethernet Interface Module RJ71EN71. Please download the fixed update file from the link "https://www.mitsubishielectric.com/fa/download/index.html" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-001_en.pdf".https://www.mitsubishielectric.com/fa/download/index.html Vendor fixMitsubishi Electric is releasing fixed version 06 or later for CC-Link IE TSN master/local Station Communication LSIs CP610 NZ2GACP610-60 and NZ2KT-NPETNG51. Please download the fixed update file from the link "https://www.mitsubishielectric.com/fa/download/index.html" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-001_en.pdf".https://www.mitsubishielectric.com/fa/download/index.html Vendor fixMitsubishi Electric is releasing fixed version 1.030 or later for MELSEC iQ-F Series FX5 CC-Link IE TSN Master/Local Module FX5-CCLGN-MS. Please download the fixed update file from the link "https://www.mitsubishielectric.com/fa/download/index.html" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-001_en.pdf".https://www.mitsubishielectric.com/fa/download/index.html Vendor fixMitsubishi Electric is releasing fixed version 1.210 or later for MELSEC iQ-F Series FX5 Ethernet Module FX5-ENET. Please download the fixed update file from the link "https://www.mitsubishielectric.com/fa/download/index.html" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-001_en.pdf".https://www.mitsubishielectric.com/fa/download/index.html Vendor fixMitsubishi Electric is releasing fixed version 1.107 or later for MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP. Please download the fixed update file from the link "https://www.mitsubishielectric.com/fa/download/index.html" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-001_en.pdf".https://www.mitsubishielectric.com/fa/download/index.html Vendor fixMitsubishi Electric is releasing fixed network part firmware version 86 or later for MELSEC iQ-R Series CPU module R04ENCPU (Network part), R08ENCPU (Network part), R16ENCPU (Network part), R32ENCPU (Network part), and R120ENCPU (Network part). Please download the fixed update file from the link "https://www.mitsubishielectric.com/fa/download/index.html" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-001_en.pdf".https://www.mitsubishielectric.com/fa/download/index.html MitigationFor customers of the affected products, Mitsubishi Electric recommends using a firewall, virtual private network (VPN), etc. to prevent unauthorized access when internet access is required, to minimize the risk of exploiting this vulnerability. MitigationFor customers of the affected products, Mitsubishi Electric recommends using within a LAN and blocking access from untrusted networks and hosts through firewalls, to minimize the risk of exploiting this vulnerability. MitigationFor customers of the affected products, Mitsubishi Electric recommends restricting physical access to the products and the LAN to which they are connected, to minimize the risk of exploiting this vulnerability. MitigationFor customers of the affected products, Mitsubishi Electric recommends installing anti-virus software on your PC that can access the affected product, to minimize the risk of exploiting this vulnerability. Relevant CWE: CWE-1284 Improper Validation of Specified Quantity in Input Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Acknowledgments Mitsubishi Electric discovering this vulnerability Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Advisory Conversion Disclaimer This ICSA is a verbatim republication of Mitsubishi Electric 2025-001 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Mitsubishi Electric directly for any questions regarding this advisory. Revision History Initial Release Date: 2025-04-25 Date Revision Summary 2025-04-25 1 CISA Republication - Initial Republication 2025-04-25 2 Initial Publication 2025-10-09 3 RJ71GN11-T2, RJ71GN11-EIP, RJ71GN11-SX, RJ71EN71, NZ2GACP610-60, and NZ2KT-NPETNG51 have been added as affected products and fixed products, and the "remediations" was revised. 2025-10-09 4 CISA Republication - Update A - Update to Affected products, Impact, Countermeasures for Customers, Countermeasures for Products have been revised. The affected products RJ71GN11-T2, RJ71GN11-EIP, RJ71GN11-SX, RJ71EN71, NZ2GACP610-60 and NZ2KT-NPETNG51 have been added. 2026-02-03 5 CISA Republication - Update B - Update to Summary, Affected products, and Remediations have been revised. The affected products FX5-CCLGN-MS, FX5-ENET, and FX5-ENET/IP have been added. 2026-02-03 6 FX5-CCLGN-MS, AFX5-ENET, and AFX5-ENET/IP have been added as affected products and fixed products, and the "remediations" was revised. 2026-04-23 7 Added FX5-CCLGN-MS and FX5-ENET/IP have been added as fixed products, and the "remediations" was revised. 2026-04-30 8 CISA Republication - Update C - Added FX5-CCLGN-MS and FX5-ENET/IP that have been fixed to Countermeasures for Products. Affected products, Countermeasures for Customers, and Countermeasures for Products have been revised. 2026-08-27 9 R04ENCPU (Network Part), R08RNCPU (Network Part), R16ENCPU (Network Part), R32ENCPU (Network Part), and R12ENCPU (Network Part) have been added as affected products and fixed products, and the "remediations" was revised. 2026-08-27 10 CISA Republication update based on Mitsubishi Electric 2025-001 advisory Legal Notice and Terms of Use
Read full story at CISA Advisories →