Mitsubishi Electric MELSEC iQ-F Series Ethernet Modules Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the Ethernet function of Mitsubishi Electric's MELSEC iQ-F Series FX5-ENET/IP Ethernet Module (versions 1.106 and prior) and the FX5-EIP EtherNet/IP Module (all versions). This vulnerability allows remote attackers to disrupt service by continuously sending UDP packets, causing the receive buffer to become depleted. As a result, the product enters a DoS state, from which recovery requires a system reset.

Impact

Exploitation of this vulnerability leads to uncontrolled consumption of the receive buffer, causing a denial-of-service condition that requires a system reset for recovery.

Remediation

Users of the FX5-ENET/IP module should update to version 1.107 or later. For the FX5-EIP module, a fixed version is expected to be released soon. Until then, users should apply the recommended mitigations. For CVE-2026-1876, there are no plans to release a fixed version, and users should also apply the suggested mitigations.

Added: Mar 3, 2026, 7:18 AM
Updated: Mar 3, 2026, 7:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
3.4
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.