Mitsubishi Electric CNC Controllers Hit by Remote DoS Vulnerability
The attack vector is the same TCP port 683 that's been targeted in prior Mitsubishi CNC advisories, patch, filter, or isolate.
TL;DR
CISA published ICSA-26-078-05 for CVE-2025-2399, an out-of-bounds read vulnerability (CWE-1285) in 18 versions of Mitsubishi Electric CNC Series controllers. A remote attacker sending crafted packets to TCP port 683 can trigger a denial-of-service condition. Fixed firmware is available for most affected product lines; M800V/M80V Series get version BC, M800/M80/E80 Series get version FN, and M700V/M70V/E70 Series get version LK. C80 and NC Trainer2 lines have no patch yet, Mitsubishi Electric recommends firewalls, VPNs, IP filters, and physical access restrictions as compensating controls.
CISA's March 19 advisory for CVE-2025-2399 is the latest in a string of Mitsubishi Electric CNC Series vulnerabilities, but it doesn't raise the stakes past what shops already contend with. The bug is an out-of-bounds read (CWE-1285, Improper Validation of Specified Index, Position, or Offset in Input) reachable by anyone who can talk to TCP port 683. The result is a crash, not code execution. CVSS v3 score: 5.9 (Medium). Attack complexity is high, and the impact is availability-only.
That doesn't make it harmless. A CNC controller that stops mid-operation means a machine tool that isn't making parts until someone resets it. For a defense supplier running a production line against a delivery schedule, that's a bad afternoon whether or not the attacker got a shell.
What's patched and what isn't
Mitsubishi Electric has released fixed firmware for three groups. The M800V/M80V Series moves to version BC or later. The M800/M80/E80 Series moves to version FN or later. The M700V/M70V/E70 Series moves to version LK or later. Every fix requires coordination with a Mitsubishi representative, no self-service firmware downloads here.
Conspicuously absent: the C80 Series and the NC Trainer2 / NC Trainer2 plus lines. Those are listed as affected with no fixed version. For those, the vendor's mitigation guidance is the full menu, firewalls, VPNs, IP filters (available on M800V/M80V and M800/M80/E80 Series), LAN-only deployment, physical access restrictions, and antivirus on connected PCs. That's a lot of compensating controls for what amounts to blocking or filtering TCP 683 traffic.
The Monday question
If you're running an affected M800V, M800, or M700V series controller, the path is straightforward: schedule the firmware update with your Mitsubishi rep and plan for downtime. If you're on C80 or NC Trainer2, the answer is less satisfying, lock down port 683 at the network boundary and wait. CISA's standard ICS guidance applies: don't expose these devices to the internet, segment control-system networks from business networks, and use VPNs when remote access is unavoidable.
Published ·Deep Fathom