Mitsubishi Electric Corporation Vulnerabilities and Affected Products
Vulnerabilities associated with MELSEC iQ-F Series FX5UC-32MT/D.
Products
Clear product- GX Works316 vulnerabilities
- GENESIS6413 vulnerabilities
- ICONICS Suite13 vulnerabilities
- MC Works6412 vulnerabilities
- MELSEC iQ-F Series FX5U-32MR/DS11 vulnerabilities
- MELSEC iQ-F Series FX5U-32MR/ES11 vulnerabilities
- MELSEC iQ-F Series FX5U-32MT/DS11 vulnerabilities
- MELSEC iQ-F Series FX5U-32MT/DSS11 vulnerabilities
- MELSEC iQ-F Series FX5U-32MT/ES11 vulnerabilities
- MELSEC iQ-F Series FX5U-32MT/ESS11 vulnerabilities
- MELSEC iQ-F Series FX5U-64MR/DS11 vulnerabilities
- MELSEC iQ-F Series FX5U-64MR/ES11 vulnerabilities
- MELSEC iQ-F Series FX5U-64MT/DS11 vulnerabilities
- MELSEC iQ-F Series FX5U-64MT/DSS11 vulnerabilities
- MELSEC iQ-F Series FX5U-64MT/ES11 vulnerabilities
- MELSEC iQ-F Series FX5U-64MT/ESS11 vulnerabilities
- MELSEC iQ-F Series FX5U-80MR/DS11 vulnerabilities
- MELSEC iQ-F Series FX5U-80MR/ES11 vulnerabilities
- MELSEC iQ-F Series FX5U-80MT/DS11 vulnerabilities
- MELSEC iQ-F Series FX5U-80MT/DSS11 vulnerabilities
- MELSEC iQ-F Series FX5U-80MT/ESS11 vulnerabilities
- MELSEC iQ-F Series FX5UC-32MR/DS-TS11 vulnerabilities
- MELSEC iQ-F Series FX5UC-32MT/D11 vulnerabilities
- MELSEC iQ-F Series FX5UC-32MT/DS-TS11 vulnerabilities
- MELSEC iQ-F Series FX5UC-32MT/DSS11 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-10259MEDIUM | Denial-of-Service(DoS) Vulnerability in TCP Communication Function on MELSEC iQ-F Series CPU moduleImproper Validation of Specified Quantity in Input vulnerability in TCP Communication Function on Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote attacker to disconnect the connection by sending specially crafted TCP packets to cause a denial-of-service (DoS) condition on the products. There is no impact on connections other than the attacked one. CWE-1284Nov 6, 2025 | CVSS5.3v3.1 | EPSS0.421% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-7731HIGH | Information Disclosure Vulnerability in MELSEC iQ-F Series CPU moduleCleartext Transmission of Sensitive Information vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote unauthenticated attacker to obtain credential information by intercepting SLMP communication messages, and read or write the device values of the product and stop the operations of programs by using the obtained credential information. CWE-319Sep 1, 2025 | CVSS7.5v3.1 | EPSS0.333% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-7405HIGH | Information Disclosure, Information Tampering, and Denial of Service (DoS) Vulnerability in MELSEC iQ-F Series CPU moduleMissing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote unauthenticated attacker to read or write the device values of the product and stop the operation of the programs, since MODBUS/TCP in the products does not have authentication features. CWE-306Sep 1, 2025 | CVSS7.3v3.1 | EPSS0.455% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-5514MEDIUM | Denial-of-Service(DoS) Vulnerability in Web server function on MELSEC iQ-F Series CPU moduleImproper Handling of Length Parameter Inconsistency vulnerability in web server function on Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote unauthenticated attacker to delay the processing of the web server function and prevent legitimate users from utilizing the web server function, by sending a specially crafted HTTP request. CWE-130Aug 25, 2025 | CVSS5.3v3.1 | EPSS0.585% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-5241MEDIUM | Denial-of-Service Vulnerability in MELSEC iQ-F SeriesOverly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series allows a remote unauthenticated attacker to lockout legitimate users for a certain period by repeatedly attempting to login with incorrect passwords. The legitimate users will be unable to login until a certain period has passed after the lockout or until the product is reset. CWE-645Jul 11, 2025 | CVSS5.3v3.1 | EPSS0.373% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-3755CRITICAL | Information Disclosure and Denial-of-Service(DoS) Vulnerability in MELSEC iQ-F Series CPU moduleImproper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules allows a remote unauthenticated attacker to read information in the product, to cause a Denial-of-Service (DoS) condition in MELSOFT connection, or to stop the operation of the CPU module (causing a DoS condtion on the CPU module), by sending specially crafted packets. The product is needed to reset for recovery. CWE-1285May 29, 2025 | CVSS9.1v3.1 | EPSS0.725% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-4699CRITICAL | Arbitrary Command Execution Vulnerability in Mitsubishi Electric proprietary protocol communication of multiple FA productsMissing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC-F Series CPU modules, MELSEC iQ-F Series, MELSEC iQ-R series CPU modules, MELSEC iQ-R series, MELSEC iQ-L series, MELSEC Q series, MELSEC-L series, Mitsubishi Electric CNC M800V/M80V series, Mitsubishi Electric CNC M800/M80/E80 series and Mitsubishi Electric CNC M700V/M70V/E70 series allows a remote unauthenticated attacker to execute arbitrary commands by sending specific packets to the affected… | CVSS10.0v3.1 | EPSS0.748% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-4625MEDIUM | Denial-of-Service(DoS) Vulnerability in Web server function on MELSEC Series CPU moduleImproper Restriction of Excessive Authentication Attempts vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F/iQ-R Series CPU modules Web server function allows a remote unauthenticated attacker to prevent legitimate users from logging into the Web server function for a certain period after the attacker has attempted to log in illegally by continuously attempting unauthorized login to the Web server function. The impact of this vulnerability will persist while the attacker continues to … CWE-307Nov 6, 2023 | CVSS5.3v3.1 | EPSS0.95% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-1424CRITICAL | Denial-of-Service and Remote Code Execution Vulnerability in MELSEC Series CPU moduleBuffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules and MELSEC iQ-R Series CPU modules allows a remote unauthenticated attacker to cause a denial of service (DoS) condition or execute malicious code on a target product by sending specially crafted packets. A system reset of the product is required for recovery from a denial of service (DoS) condition and malicious code execution. CWE-120May 24, 2023 | CVSS10.0v3.1 | EPSS3.44% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-0457HIGH | Information Disclosure Vulnerability in MELSEC SeriesPlaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series, MELSEC iQ-R Series, MELSEC-Q Series and MELSEC-L Series allows a remote unauthenticated attacker to disclose plaintext credentials stored in project files and login into FTP server or Web server. | CVSS7.5v3.1 | EPSS1.17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-40267MEDIUM | Authentication Bypass Vulnerability in Web Server Function on MELSEC SeriesPredictable Seed in Pseudo-Random Number Generator (PRNG) vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5U-xMy/z (x=32,64,80, y=T,R, z=ES,DS,ESS,DSS) with serial number 17X**** or later, and versions 1.280 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5U-xMy/z (x=32,64,80, y=T,R, z=ES,DS,ESS,DSS) with serial number 179**** and prior, and versions 1.074 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UC-xMy/z (x=32,64,96, y=T, z=D,DSS)) w… | CVSS5.9v3.1 | EPSS1.18% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |