Mitsubishi Electric Multiple FA Products (Update D)
Mitsubishi Electric FA products vulnerable to DoS via crafted UDP packets.
Summary
A denial-of-service vulnerability (CVE-2025-3511) has been identified in multiple Mitsubishi Electric FA products. Exploitation could allow a remote attacker to cause a DoS condition, timeout error, or communication delay by sending a specially crafted UDP packet. Affected products include various CC-Link IE TSN modules and communication LSIs. Mitsubishi Electric has released updated versions and recommends network segmentation and firewalling as mitigations.
Full text
ICS Advisory Mitsubishi Electric Multiple FA Products (Update D) Last RevisedApril 30, 2026 Alert CodeICSA-25-128-03 Related topics: Industrial Control System Vulnerabilities , Industrial Control Systems View CSAF Summary Successful exploitation of this vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition, a timeout error, or a communication delay by sending a specially crafted UDP packet to the product. The following versions of Mitsubishi Electric Multiple FA Products (Update D) are affected: Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32D <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32T <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32TE <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32DT <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32DTE <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32D <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32T <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32TE <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32DT <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32DTE <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GNCF1-32D <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GNCF1-32T <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GNCE3-32D <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GNCE3-32DT <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A4-16D <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A4-16DE <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A2-16T <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A2-16TE <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A42-16DT <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A42-16DTE <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-16D <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-16T <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-16TE <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-16D <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-16T <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-16TE <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Analog-Digital Converter module NZ2GN2S-60AD4 <=07 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Analog-Digital Converter module NZ2GN2B-60AD4 <=07 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Digital-Analog Converter module NZ2GN2S-60DA4 <=07 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Digital-Analog Converter module NZ2GN2B-60DA4 <=07 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN FPGA module NZ2GN2S-D41P01 01 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN FPGA module NZ2GN2S-D41D01 01 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN FPGA module NZ2GN2S-D41PD02 01 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote Station Communication LSI CP620 with GbE-PHY NZ2GACP620-300 <=1.08J (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote Station Communication LSI CP620 with GbE-PHY NZ2GACP620-60 <=1.08J (CVE-2025-3511) Mitsubishi Electric MELSEC iQ-R Series CC-Link IE TSN Master/Local Module RJ71GN11-T2 <=26 (CVE-2025-3511) Mitsubishi Electric MELSEC iQ-R Series CC-Link IE TSN Master/Local Module RJ71GN11-EIP <=10 (CVE-2025-3511) Mitsubishi Electric MELSEC iQ-R Series CC-Link IE TSN Master/Local Module RJ71GN11-SX <=05 (CVE-2025-3511) Mitsubishi Electric MELSEC iQ-R Series Ethernet Interface Module RJ71EN71 <=85 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN master/local Station Communication LSI CP610 NZ2GACP610-60 <=05 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN master/local Station Communication LSI CP610 NZ2KT-NPETNG51 <=05 (CVE-2025-3511) Mitsubishi Electric MELSEC iQ-F Series FX5 CC-Link IE TSN Master/Local Module FX5-CCLGN-MS <=1.020 (CVE-2025-3511) Mitsubishi Electric MELSEC iQ-F Series FX5 Ethernet Module FX5-ENET <=1.200 (CVE-2025-3511) Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP <=1.106 (CVE-2025-3511) Mitsubishi Electric MELSEC iQ-R Series CPU module R04ENCPU (Network Part) <=85 (CVE-2025-3511) Mitsubishi Electric MELSEC iQ-R Series CPU module R08ENCPU (Network Part) <=85 (CVE-2025-3511) Mitsubishi Electric MELSEC iQ-R Series CPU module R16ENCPU (Network Part) <=85 (CVE-2025-3511) Mitsubishi Electric MELSEC iQ-R Series CPU module R32ENCPU (Network Part) <=85 (CVE-2025-3511) Mitsubishi Electric MELSEC iQ-R Series CPU module R120ENCPU (Network Part) <=85 (CVE-2025-3511) CVSS Vendor Equipment Vulnerabilities v3 7.5 Mitsubishi Electric Mitsubishi Electric Multiple FA Products (Update D) Improper Validation of Specified Quantity in Input Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Japan Vulnerabilities Expand All + CVE-2025-3511 A denial-of-service (DoS) vulnerability due to Improper Validation of Specified Quantity in Input (CWE-1284) exists in the Ethernet function of multiple FA products. This vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition by sending a specially crafted UDP packet if CC-Link IE TSN Remote I/O modules NZ2GN2S1-32D, NZ2GN2S1-32T, NZ2GN2S1-32TE, NZ2GN2S1-32DT, NZ2GN2S1-32DTE, NZ2GN2B1-32D, NZ2GN2B1-32T, NZ2GN2B1-32TE, NZ2GN2B1-32DT, NZ2GN2B1-32DTE, NZ2GNCF1-32D, NZ2GNCF1-32T, NZ2GNCE3-32D, NZ2GNCE3-32DT, NZ2GN12A4-16D, NZ2GN12A4-16DE, NZ2GN12A2-16T, NZ2GN12A2-16TE, NZ2GN12A42-16DT, NZ2GN12A42-16DTE, NZ2GN2S1-16D, NZ2GN2S1-16T, NZ2GN2S1-16TE, NZ2GN2B1-16D, NZ2GN2B1-16T, NZ2GN2B1-16TE, CC-Link IE TSN Analog-Digital Converter modules NZ2GN2S-60AD4, NZ2GN2B-60AD4, CC-Link IE TSN Digital-Analog Converter modules NZ2GN2S-60DA4 and NZ2GN2B-60DA4, CC-Link IE TSN FPGA modules NZ2GN2S-D41P01, NZ2GN2S-D41D01, NZ2GN2S-D41PD02, CC-Link IE TSN Remote Station Communication LSIs CP620 with GbE-PHY NZ2GACP620-300, and NZ2GACP620-60 does not receive a valid UDP packet within 3 seconds. This vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition on MELSEC iQ-R Series CC-Link IE TSN Master/Local Module RJ71GN11-T2, RJ71GN11-EIP, RJ71GN11-SX, MELSEC iQ-R Series Ethernet Interface Module RJ71EN71, CC-Link IE TSN master/local Station Communication LSIs CP610 NZ2GACP610-60, NZ2KT-NPETNG51, MELSEC iQ-F Series FX5 CC-Link IE TSN Master/Local Module FX5-CCLGN-MS, MELSEC iQ-R Series CPU module R04ENCPU (Network part), R08ENCPU (Network part), R16ENCPU (Network part), R32ENCPU (Network part), and R120ENCPU (Network part), by sending a specially crafted UDP packet. Or this vulnerability could allow a remote attacker to cause a communication delay in Simple CPU communication on MELSEC iQ-F Series FX5 Ethernet Module FX5-ENET and FX5-ENET/IP Ethernet Module FX5-ENET/IP, by sending a specially crafted UDP packet. A system reset of the product is required for recovery in all cases above. Additionally, this vulnerability could allow a remote attacker to cause a timeout error in CC-Link IEF Basic communication on MELSEC iQ-F Series FX5 Ethernet Module FX5-ENET and FX5-ENET/IP Ethernet Module FX5-ENET/IP, by sending a specially crafted UDP packet. Even if a timeout error occurs, communication will be restored once the affected product starts receiving valid UDP packets. View CVE Details Affected Products Mitsubishi
Indicators of Compromise
- cve — CVE-2025-3511