← Back to home
ICSA-25-266-02  ·  Published 2025-09-23  ·  View on CISA ICS-CERT ↗

Mitsubishi Electric MELSEC-Q Series CPU Module

CVSS 6.8 MEDIUM

Risk Summary

Successful exploitation of this vulnerability could allow an attacker to cause a denial of service (DoS).

CVEs (1)

Remediations

  • Mitsubishi Electric has released the fixed version as shown below, but updating the product to the fixed version is currently unavailable. Consider migrating to the successor model, MELSEC iQ-R Series.
  • MELSEC-QSeries Q03UDVCPU: The first 5 digits of serial No. '27082' or later.
  • MELSEC-QSeries Q04UDVCPU: The first 5 digits of serial No. '27082' or later.
  • MELSEC-QSeries Q06UDVCPU: The first 5 digits of serial No. '27082' or later.
  • MELSEC-QSeries Q13UDVCPU: The first 5 digits of serial No. '27082' or later.
  • MELSEC-QSeries Q26UDVCPU: The first 5 digits of serial No. '27082' or later.
  • MELSEC-QSeries Q04UDPVCPU: The first 5 digits of serial No. '27082' or later.
  • MELSEC-QSeries Q06UDPVCPU: The first 5 digits of serial No. '27082' or later.
  • MELSEC-QSeries Q13UDPVCPU: The first 5 digits of serial No. '27082' or later.
  • MELSEC-QSeries Q26UDPVCPU: The first 5 digits of serial No. '27082' or later.
  • Mitsubishi Electric recommends users employ the following mitigation measures to minimize the risk of vulnerability exploit.
  • Use a firewall or virtual private network (VPN), etc. to prevent unauthorized access when Internet access is required.
  • Use within a LAN and block access from untrusted networks and hosts through firewalls.
  • Restrict physical access to the affected products, as well as to computers and network devices that can be connected to those products.
  • See Mitsubishi Electric's security bulletin for more information.

Affected Vendors

Mitsubishi Electric

Affected Products (9)

Mitsubishi Electric · MELSEC-Q Series Q03UDVCPU >=The_first_5_digits_of_serial_No._'24082'|<'27081'
Mitsubishi Electric · MELSEC-Q Series Q04UDVCPU >=The_first_5_digits_of_serial_No._'24082'|<'27081'
Mitsubishi Electric · MELSEC-Q Series Q06UDVCPU >=The_first_5_digits_of_serial_No._'24082'|<'27081'
Mitsubishi Electric · MELSEC-Q Series Q13UDVCPU >=The_first_5_digits_of_serial_No._'24082'|<'27081'
Mitsubishi Electric · MELSEC-Q Series Q26UDVCPU >=The_first_5_digits_of_serial_No._'24082'|<'27081'
Mitsubishi Electric · MELSEC-Q Series Q04UDPVCPU >=The_first_5_digits_of_serial_No._'24082'|<'27081'
Mitsubishi Electric · MELSEC-Q Series Q06UDPVCPU >=The_first_5_digits_of_serial_No._'24082'|<'27081'
Mitsubishi Electric · MELSEC-Q Series Q13UDPVCPU >=The_first_5_digits_of_serial_No._'24082'|<'27081'
Mitsubishi Electric · MELSEC-Q Series Q26UDPVCPU >=The_first_5_digits_of_serial_No._'24082'|<'27081'

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more