IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Mitsubishi Electric CNC Series (Update A)

MEDIUM
CVSS 5.9
Date 2026-08-27T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of this vulnerability could allow a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition in the affected products.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2025-2399 5.9 medium
Improper Validation of Specified Index, Position, or Offset in Input (CWE-1285) vulnerability in the affected products allows a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition in the affected products by sending specially crafted packets to TCP port 683.

// Remediations (8)

Mitigation: For customers of products that do not have a fixed version or who cannot immediately update the prod
For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric recommends installing anti-virus software on PCs that can access the affected product, to minimize the risk of exploiting this vulnerability.
Patch: Please apply the fixed version (FN or later) for Mitsubishi Electric M800W (BND-2005W000), M800S (BN
Please apply the fixed version (FN or later) for Mitsubishi Electric M800W (BND-2005W000), M800S (BND-2006W000), M80 (BND-2007W000), M80W (BND-2008W000), and E80 (BND-2009W000). For instructions on how to apply it, please consult your Mitsubishi Electric representative.
Patch: Please apply the fixed version (LK or later) for Mitsubishi Electric M750VW (BND-1015W002), M730VW (
Please apply the fixed version (LK or later) for Mitsubishi Electric M750VW (BND-1015W002), M730VW (BND-1015W000), M720VW (BND-1015W000), M750VS (BND-1012W002), M730VS (BND-1012W000), M720VS (BND-1012W000), M70V (BND-1018W000), and E70 (BND-1022W000). For instructions on how to apply it, please consult your Mitsubishi Electric representative.
Mitigation: For customers of products that do not have a fixed version or who cannot immediately update the prod
For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric recommends restricting physical access to the affected product and to all computers and network devices to which the products are connected, to minimize the risk of exploiting this vulnerability.
Mitigation: For customers of products that do not have a fixed version or who cannot immediately update the prod
For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric recommends using a firewall or virtual private network (VPN) to prevent unauthorized access, when internet access is required, to minimize the risk of exploiting this vulnerability.
Mitigation: For customers of products that do not have a fixed version or who cannot immediately update the prod
For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric recommends using IP filters to prevent unauthorized access, when internet access is required, to minimize the risk of exploiting this vulnerability. IP filter function is available for M800V/M80V Series and M800/M80/E80 Series. For details about the IP filter function, refer to the following manual for each product which can be downloaded from the link "https://www.mitsubishielectric.com/fa/download/index.html ": M800V/M80V Series Instruction Manual "16. Appendix 3 IP Address Filter Setting Function", M800/M80/E80 Series Instruction Manual "15. Appendix 2 IP Address Filter Setting Function".
Mitigation: For customers of products that do not have a fixed version or who cannot immediately update the prod
For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric recommends using the product within a LAN and blocking access from untrusted networks and hosts through a firewall, to minimize the risk of exploiting this vulnerability.
Patch: Please apply the fixed version (BC or later) for Mitsubishi Electric M800VW (BND-2051W000), M800VS (
Please apply the fixed version (BC or later) for Mitsubishi Electric M800VW (BND-2051W000), M800VS (BND-2052W000), M80V (BND-2053W000), and M80VW (BND-2054W000). For instructions on how to apply it, please consult your Mitsubishi Electric representative.

// References