VYPR
Unrated severityNVD Advisory· Published Jun 2, 2022· Updated Aug 3, 2024

CVE-2022-25163

CVE-2022-25163

Description

Improper input validation in Mitsubishi Electric MELSEC-Q/L Ethernet units and iQ-R MES unit allows unauthenticated remote DoS or code execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Improper input validation in Mitsubishi Electric MELSEC-Q/L Ethernet units and iQ-R MES unit allows unauthenticated remote DoS or code execution.

Vulnerability

An improper input validation vulnerability (CWE-20) exists in the Web function of Mitsubishi Electric MELSEC-Q Series QJ71E71-100 (serial number first 5 digits "24061" or prior), MELSEC-L Series LJ71E71-100 (serial number first 5 digits "24061" or prior), and the REST server function of MELSEC iQ-R Series RD81MES96N (firmware version "08" or prior). The vulnerability is triggered when specially crafted packets are received by the affected device [1].

Exploitation

An unauthenticated remote attacker can send specially crafted packets to the target device without needing any prior authentication or network position beyond network access. The attacker must be able to reach the network interface of the affected unit and send the malicious payload. No user interaction is required [1].

Impact

Successful exploitation can cause a denial of service (DoS) condition on the device or allow the attacker to execute arbitrary malicious code. The impact compromises availability and potentially integrity and confidentiality, depending on the attacker's payload [1].

Mitigation

As of the publication date (2022-06-02), the vendor Mitsubishi Electric has not released a fix or workaround in the available references. Users are advised to contact Mitsubishi Electric for updated firmware or mitigation guidance. No version beyond the affected serial numbers or firmware version has been announced as fixed [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

0

No linked articles in our index yet.