THE CISA advisory ICSA-25-128-03, updated on April 30, 2026, addresses a critical vulnerability (CVE-2025-3511) in multiple Mitsubishi Electric FA products that could allow remote attackers to cause denial-of-service (DoS) conditions. The vulnerability arises from improper validation of input data when processing UDP packets. Numerous models of CC-Link IE TSN Remote I/O modules, Analog-Digital and Digital-Analog Converter modules, and MELSEC iQ series CPU modules are affected.
CISA urges users to implement fixes provided by Mitsubishi Electric and take defensive measures such as using firewalls and restricting network access to mitigate risks.