CVE-2025-3511
Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module, CC-Link IE TSN Analog-Digital Converter module, CC-Link IE TSN Digital-Analog Converter module, CC-Link IE TSN FPGA module, CC-Link IE TSN Remote Station Communication LSI CP620 with GbE-PHY, MELSEC iQ-R Series CC-Link IE TSN Master/Local Module, MELSEC iQ-R Series Ethernet Interface Module, CC-Link IE TSN Master/Local Station Communication LSI CP610, MELSEC iQ-F Series FX5 CC-Link IE TSN Master/Local Module, MELSEC iQ-F Series FX5 Ethernet Module, and MELSEC iQ-F Series FX5-ENET/IP Ethernet Module allows a remote unauthenticated attacker to cause a Denial of Service condition in the products by sending specially crafted UDP packets.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.88%
- CWE
- CWE-1284
- Published
- 2025-04-25
- Last modified
- 2026-08-27
Affected products
- Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module NZ2GN2S1-32D
- Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module NZ2GN2S1-32T
- Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module NZ2GN2S1-32TE
- Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module NZ2GN2S1-32DT
- Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module NZ2GN2S1-32DTE
- Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module NZ2GN2B1-32D
- Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module NZ2GN2B1-32T
- Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module NZ2GN2B1-32TE
Weakness type
Related vulnerabilities
- CVE-2025-9316 — N-central unauthenticated sessionID generation
- CVE-2026-87470 — Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to pote
- CVE-2023-54337 — Sysax Multi Server 6.95 - 'Password' Denial of Service (PoC)
- CVE-2026-21485 — iccDEV Undefined Behavior (UB) and Out of Memory in CIccProfile::LoadTag()
- CVE-2025-8320 — Tesla Wall Connector Content-Length Header Improper Input Validation Remote Code Execution Vulnerability
- CVE-2025-15080 — Information Disclosure, Information Tampering, and Denial of Service (DoS) Vulnerability in Mitsubishi Electric proprietary protocol communication and SLMP communication for FA products
- CVE-2025-14869 — Improper Validation of Specified Quantity in Input in GitLab
- CVE-2025-8424 — Improper access control on the NetScaler Management Interface