Skip to content
  • NVDA
  • AAPL
  • MSFT
  • AMD
  • TSLA

Mitsubishi Electric FA Products Vulnerable to DoS via UDP

CISA advisory details denial-of-service vulnerability in multiple Mitsubishi Electric FA products.

By TMRO Staff·1 min read

Key points

  • CISA advisory published 2026-08-27
  • Affects CC-Link IE TSN Remote I/O modules
  • Remote attacker can cause DoS or timeout
  • Vulnerability tracked as CVE-2025-3511
  • Update D of advisory

What happened

CISA released an advisory on August 27, 2026, regarding a vulnerability in multiple Mitsubishi Electric FA products. The advisory, titled "Mitsubishi Electric Multiple FA Products (Update D)", identifies CVE-2025-3511 as affecting CC-Link IE TSN Remote I/O modules NZ2GN2S1-32D, NZ2GN2S1-32T, and NZ2GN2S1-32TE, all versions up to and including 09.

The vulnerability allows a remote attacker to send a specially crafted UDP packet to the product, potentially causing a denial-of-service (DoS) condition, a timeout error, or a communication delay.

Why it matters

These remote I/O modules are used in industrial control systems. Exploitation could disrupt critical processes, leading to operational downtime. Organizations using affected versions should review the advisory and apply any available patches or workarounds to mitigate the risk.

Why it matters

These modules are used in industrial automation environments. A remote attacker exploiting this vulnerability could disrupt operations, leading to downtime or safety risks. Organizations using affected products should apply mitigations or updates as recommended by Mitsubishi Electric.

Sources

TMRO Report writes original coverage based on the material listed above.