CVE-2020-5547
Description
A resource management error in Mitsubishi Electric MELQIC IU1 series firmware allows remote attackers to disrupt network functions or execute malware via a crafted packet.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A resource management error in Mitsubishi Electric MELQIC IU1 series firmware allows remote attackers to disrupt network functions or execute malware via a crafted packet.
Vulnerability
A resource management errors vulnerability (CWE-399) exists in the TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D devices running firmware version 1.0.7 and earlier [1]. The vulnerability allows an attacker to send a specially crafted packet that triggers improper resource handling, potentially leading to a denial of service or arbitrary code execution.
Exploitation
An attacker in a position to send network packets to the vulnerable device can exploit this vulnerability without authentication [1]. The crafted packet must be delivered over the network to the affected TCP function, causing the resource management error.
Impact
Successful exploitation can stop the network functions of the product, leading to a denial of service, or allow the execution of malware [1]. This could result in full compromise of the device's operation.
Mitigation
The developer has released firmware version 1.08 or later, which addresses this vulnerability. Upgrading requires IU Configuration Tool version 1.04 or later [1]. As a workaround, restricting network access from untrusted networks and hosts via a firewall may reduce risk [1].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=1.0.7
- Range: IU1-1M20-D firmware version 1.0.7 and earlier
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
2- jvn.jp/en/vu/JVNVU92370624/index.htmlmitrex_refsource_MISC
- www.mitsubishielectric.co.jp/psirt/vulnerability/pdf/2019-004.pdfmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.