Executive brief
The Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP is an Ethernet module used in industrial automation to manage communications for programmable logic controllers (PLCs). A vulnerability in this module allows a remote attacker to crash the device's communication functions by flooding it with network traffic. This results in a denial-of-service (DoS) condition that can disrupt industrial processes and prevent the system from detecting other operational anomalies.
Technical details
An 'Expected Behavior Violation' (CWE-440) exists in the Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module. The vulnerability is triggered when the device receives a continuous stream of a large number of communication packets at its Ethernet port over a short duration. This flood increases the processing load to a point where internal anomaly-detection mechanisms fail and the communication function stops entirely. The attack can be launched remotely over the network without authentication. Mitsubishi Electric has stated that no firmware updates are planned for this module; instead, users are advised to implement network segmentation, IP filtering, and firewalls to mitigate the risk.
Affected products
- Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP All versions
Timeline
- 2026-06-18: advisory: CISA and Mitsubishi Electric published advisories.
- 2026-06-19: disclosed: JVN advisory published.