Mitsubishi Electric MELSEC iQ-F Series TCP Communication Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the TCP communication function of the Mitsubishi Electric MELSEC iQ-F Series CPU module. This vulnerability allows remote attackers to disconnect an active connection by sending specially crafted TCP packets, creating a DoS condition on the affected product. Notably, this issue only impacts the connection under attack, with no effects on other active connections.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition, where the targeted TCP connection is abruptly disconnected. To recover from this state, the connection must be manually re-established.

Remediation

Mitsubishi Electric has no plans to release a fixed version for this vulnerability. Instead, the company recommends using a virtual private network (VPN) to encrypt communications when Internet access is necessary, and restricting physical access to the affected products and their connected LAN.

Added: Nov 6, 2025, 8:20 AM
Updated: Nov 6, 2025, 8:20 AM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
2.5
exploitability
7.0
remediation
7.9
relevance
0.9
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.