CVE-2026-8806 Details
Description
Expected Behavior Violation vulnerability in Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP all versions allows a remote attacker to cause a denial-of-service (DoS) condition in the affected product by continuously sending a large number of communication packets to the Ethernet port of the product in a short period of time, increasing the processing load of the product, preventing the internal anomaly-detection processing from being performed, and causing the communication function to stop.
A denial-of-service vulnerability has been identified in the Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module, affecting all versions. This vulnerability allows remote attackers to disrupt the communication function of the device by flooding its Ethernet port with a high volume of packets in a short time frame. This surge in traffic increases the device's processing load, interferes with its internal anomaly-detection capabilities, and ultimately causes the communication function to fail.
Mitsubishi Electric does not plan to release a fixed version for this vulnerability. However, customers are advised to migrate to the successor model, the FX5-EIP EtherNet/IP Module FX5-EIP. For those who continue to use the FX5-ENET/IP module, it is recommended to use a firewall or VPN to block unauthorized access, restrict access from untrusted networks, and utilize the IP filter function to block untrusted hosts. Physical access to the module and connected devices should also be limited.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 19, 2026CISA-ADP
Assessed Jun 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jvn.jp/vu/JVNVU97140216/ | [email protected] | AdvisoryBroken Link |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-169-06 | [email protected] | AdvisoryBundleRemedy |
| https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-003_en.pdf | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-440 | Expected Behavior Violation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP | <all versions> |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 19, 2026 | New CVE Received | [email protected] |
Volerion