www.cisa.gov 8/27/2026, 4:51:27 PM · external

Mitsubishi Electric Multiple FA Products (Update D)

CyberSIXT Evidence Panel
Primary Source github.com
CISA KEV Not in KEV
Patch Patch Status Unknown

THE CISA advisory ICSA-25-128-03, updated on April 30, 2026, addresses a critical vulnerability (CVE-2025-3511) in multiple Mitsubishi Electric FA products that could allow remote attackers to cause denial-of-service (DoS) conditions. The vulnerability arises from improper validation of input data when processing UDP packets. Numerous models of CC-Link IE TSN Remote I/O modules, Analog-Digital and Digital-Analog Converter modules, and MELSEC iQ series CPU modules are affected.

CISA urges users to implement fixes provided by Mitsubishi Electric and take defensive measures such as using firewalls and restricting network access to mitigate risks.

View Primary Source Via www.cisa.gov

Article by CyberSIXT