VYPR
advisoryPublished Aug 27, 2026· 1 source

CISA Warns of Denial-of-Service Vulnerability in Mitsubishi Electric FA Products

CISA has issued an advisory for multiple Mitsubishi Electric CC-Link IE TSN products affected by CVE-2025-3511, which can lead to denial-of-service conditions.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released a critical advisory detailing a denial-of-service (DoS) vulnerability affecting a wide range of Mitsubishi Electric CC-Link IE TSN products. The vulnerability, identified as CVE-2025-3511, stems from an improper validation of specified quantities in input, a common weakness categorized under CWE-1284.

Successful exploitation of this flaw allows a remote attacker to disrupt operations by sending a specially crafted UDP packet to the affected devices. This malicious packet can trigger a denial-of-service condition, cause a timeout error, or introduce communication delays, potentially leading to significant operational disruptions in industrial environments. The vulnerability specifically targets the Ethernet function within these products.

The advisory lists an extensive array of affected Mitsubishi Electric products, primarily focusing on CC-Link IE TSN Remote I/O modules, converter modules, FPGA modules, and communication LSI modules. Versions up to and including '09' for many Remote I/O modules, '07' for Analog-Digital and Digital-Analog Converter modules, '01' for specific FPGA modules, and '1.08J' for CP620 communication LSI modules are confirmed to be vulnerable. Other affected product lines include MELSEC iQ-R Series modules (Master/Local, Ethernet Interface) and MELSEC iQ-F Series modules (CC-Link IE TSN Master/Local, Ethernet).

This vulnerability poses a significant risk to critical infrastructure sectors, particularly in critical manufacturing, where these products are widely deployed. The global reach of Mitsubishi Electric's industrial automation solutions means that organizations worldwide could be impacted. The CVSS score for this vulnerability is rated at 7.5, indicating a high severity level.

CISA has not yet indicated whether this vulnerability has been actively exploited in the wild, but the potential for disruption warrants immediate attention from operators of these systems. The advisory provides a comprehensive list of affected product models and their specific vulnerable version ranges, enabling organizations to identify their exposure.

While the advisory does not explicitly detail vendor-provided patches or workarounds, it strongly recommends that users review the CSAF (Cybersecurity Advisory Format) summary for detailed mitigation strategies. Organizations using these Mitsubishi Electric products are urged to consult the official CISA advisory and Mitsubishi Electric's security advisories for the latest information on remediation and protective measures.

The disclosure of CVE-2025-3511 underscores the ongoing cybersecurity challenges faced by the industrial control systems (ICS) and operational technology (OT) sectors. Vulnerabilities in widely used industrial hardware can have cascading effects, impacting production lines, supply chains, and critical services. Proactive security management, including regular vulnerability assessments and timely patching, remains paramount for securing these environments.

Synthesized by Vypr AI