CVE-2025-3511 Details
Description
Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module, CC-Link IE TSN Analog-Digital Converter module, CC-Link IE TSN Digital-Analog Converter module, CC-Link IE TSN FPGA module, CC-Link IE TSN Remote Station Communication LSI CP620 with GbE-PHY, MELSEC iQ-R Series CC-Link IE TSN Master/Local Module, MELSEC iQ-R Series Ethernet Interface Module, CC-Link IE TSN Master/Local Station Communication LSI CP610, MELSEC iQ-F Series FX5 CC-Link IE TSN Master/Local Module, MELSEC iQ-F Series FX5 Ethernet Module, MELSEC iQ-F Series FX5-ENET/IP Ethernet Module, and MELSEC iQ-R Series CPU module allows a remote unauthenticated attacker to cause a Denial of Service condition in the products by sending specially crafted UDP packets.
A denial-of-service vulnerability has been identified in multiple CC-Link IE TSN products, including Remote I/O modules, Analog-Digital and Digital-Analog Converter modules, FPGA modules, and the CC-Link IE TSN Remote Station Communication LSI CP620 with GbE-PHY. This vulnerability allows a remote, unauthenticated attacker to disrupt the normal operation of the affected products by sending specially crafted UDP packets. The issue arises from improper validation of input quantity, which can lead to a condition where the product fails to process valid UDP packets within a specified timeframe, causing a system reset and requiring manual recovery.
Users can update to the fixed versions of the affected products. For the CC-Link IE TSN Remote Station Communication LSI CP620 with GbE-PHY, version 1.09K or later is recommended. Detailed update procedures are available in the 'CC-Link IE TSN Firmware Update Tool Reference Manual' and on the Mitsubishi Electric FA download page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 25, 2025CISA-ADP
Assessed Oct 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1284 | Improper Validation of Specified Quantity in Input | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Mitsubishi Electric CC-Link IE TSN Remote I/O module | All versions |
CPE
Remediation
| |
| Mitsubishi Electric CC-Link IE TSN Analog-Digital Converter module | All versions |
CPE
Remediation
| |
| Mitsubishi Electric CC-Link IE TSN Digital-Analog Converter module | All versions |
CPE
Remediation
| |
| Mitsubishi Electric CC-Link IE TSN FPGA module | All versions |
CPE
Remediation
| |
| Mitsubishi Electric CC-Link IE TSN Remote Station Communication LSI CP620 | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 27, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 5, 2026 | CVE Modified | [email protected] |
| Oct 10, 2025 | CVE Modified | [email protected] |
| Apr 25, 2025 | New CVE Received | [email protected] |
Volerion