What happened
CISA released an advisory on August 27, 2026, regarding a vulnerability in multiple Mitsubishi Electric FA products. The advisory, titled "Mitsubishi Electric Multiple FA Products (Update D)", identifies CVE-2025-3511 as affecting CC-Link IE TSN Remote I/O modules NZ2GN2S1-32D, NZ2GN2S1-32T, and NZ2GN2S1-32TE, all versions up to and including 09.
The vulnerability allows a remote attacker to send a specially crafted UDP packet to the product, potentially causing a denial-of-service (DoS) condition, a timeout error, or a communication delay.
Why it matters
These remote I/O modules are used in industrial control systems. Exploitation could disrupt critical processes, leading to operational downtime. Organizations using affected versions should review the advisory and apply any available patches or workarounds to mitigate the risk.