Mitsubishi CC-Link IE TSN modules vulnerable to remote DoS
A single crafted UDP packet can trigger denial-of-service across 30-plus industrial I/O, converter, and communication LSI models, recovery requires a system reset.
TL;DR
CISA published ICS advisory ICSA-25-128-03 for CVE-2025-3511, an improper input validation flaw (CWE-1284) in Mitsubishi Electric's CC-Link IE TSN remote I/O modules, analog-digital and digital-analog converters, FPGA modules, communication LSIs, and MELSEC iQ-R and iQ-F series master/local and CPU modules. A remote attacker can cause DoS, timeout errors, or communication delays by sending a specially crafted UDP packet. Affected firmware versions are 09 or earlier for I/O modules, 07 or earlier for converter modules, and varying ceilings for communication and CPU modules. Mitsubishi recommends updating firmware and (where updates aren't available) applying network segmentation and firewall filtering as interim mitigations.
CVE-2025-3511 sits in the Ethernet function of Mitsubishi's CC-Link IE TSN product line. The vulnerability (classified as CWE-1284, Improper Validation of Specified Quantity in Input) lets a remote attacker disrupt operations with a single crafted UDP packet. The impact varies by module type. On remote I/O modules, converter modules, FPGA modules, and communication LSIs, the result is a denial-of-service condition that requires a system reset. On MELSEC iQ-F series FX5 Ethernet and FX5-ENET/IP modules, the same attack vector can produce a timeout error in CC-Link IEF Basic communication or a communication delay in Simple CPU communication.
Mitsubishi's advisory directs users to update firmware where available. For products where firmware hasn't been released yet, the vendor recommends network segmentation (isolating affected devices behind firewalls) and restricting physical access. Blocking UDP traffic from untrusted networks to the affected interfaces is the immediate operational lever while waiting for patched firmware. CISA's advisory incorporates these same mitigation steps without adding independent guidance.
The affected surface is broad: the CVE covers more than 30 module variants spanning I/O, analog conversion, FPGAs, communication LSIs, and master/local and CPU modules in both the iQ-R and iQ-F series. For a production environment running multiple CC-Link IE TSN components, a single unpatched module could become the ingress point that forces a line reset.
This is a routine ICS advisory, the CVSS v3 base score is 7.5, network-exploitable with low attack complexity and no authentication. No evidence of active exploitation is included in the advisory. But for defense contractors and manufacturers with these modules on factory floors, the absence of patched firmware for some variants means the mitigation is operational discipline, not a download.
Published ·Deep Fathom