MELSEC iQ-F Series Vulnerability Exposes Systems to Denial-of-Service Attacks
Mitsubishi Electric's MELSEC iQ-F Series FX5-EIP EtherNet/IP Module has been found vulnerable to an integer overflow issue that can lead to denial-of-service (DoS) conditions. This vulnerability, identified as CVE-2026-8805, affects versions 1.000 and prior of the module. A similar DoS vulnerability exists in the FX5-ENET/IP Ethernet Module across all versions, noted as CVE-2026-8806. Immediate action is recommended for affected systems to mitigate potential disruptions.
Summary
Mitsubishi Electric has disclosed vulnerabilities affecting its MELSEC iQ-F Series FX5-EIP EtherNet/IP Module and FX5-ENET/IP Ethernet Module. The identified vulnerability in the FX5-EIP module, CVE-2026-8805, stems from an integer overflow or wraparound issue that allows a remote attacker to cause a denial-of-service (DoS) condition by rapidly establishing numerous TCP connections. This results in inconsistencies within the internal connection management process and triggers improper memory access.
Similarly, the FX5-ENET/IP module is affected by CVE-2026-8806, where an attacker can induce a DoS state by sending a large volume of communication packets over a short period. This leads to increased processing load, failure in anomaly detection, and cessation of communication functions.
What happened
The vulnerabilities were identified through coordinated efforts between Mitsubishi Electric and cybersecurity agencies like CISA. The CVE-2026-8805 vulnerability specifically affects the EtherNet/IP function of the FX5-EIP module versions 1.000 and earlier by exploiting integer overflow in connection management. This allows attackers to disrupt service operations significantly.
For the FX5-ENET/IP module, identified as CVE-2026-8806, the issue arises from the system's inability to handle excessive communication packets efficiently, leading to a similar DoS condition. The vulnerabilities were disclosed publicly on June 18, 2026, with advisories issued by CISA and detailed in Mitsubishi Electric's security bulletin.
Technical details
CVE-2026-8805 involves an integer overflow vulnerability that occurs when the EtherNet/IP function of the FX5-EIP module processes a large number of TCP connections. This causes inconsistencies in connection management and improper memory access, leading to service disruption.
In CVE-2026-8806, the vulnerability is due to the system's inability to manage high volumes of communication packets efficiently. The excessive load results in processing failures and halts communication functions, causing a DoS state.
Affected products and fixed versions
The affected product for CVE-2026-8805 is the Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP Module (FX5-EIP), specifically version 1.000 and earlier. For CVE-2026-8806, all versions of the FX5-ENET/IP Ethernet Module are vulnerable.
| Product | Vulnerable Versions | Fixed Version |
|---|---|---|
| FX5-EIP | 1.000 and prior | Updated version available |
| FX5-ENET/IP | All versions | No fix planned; mitigation recommended |
Exploitation status
The vulnerabilities are actively exploitable, with potential for denial-of-service attacks on affected systems. The CVE-2026-8805 vulnerability can be triggered by establishing numerous TCP connections rapidly, while CVE-2026-8806 exploits the system's inability to handle excessive communication packets.
Detection opportunities
Organizations using these modules should implement network monitoring to detect unusual patterns of TCP connection requests or high volumes of packet traffic. Intrusion detection systems (IDS) configured with specific rules for these vulnerabilities can help identify potential exploitation attempts.
Timeline
- June 18, 2026: Vulnerabilities disclosed publicly.
- Post-disclosure: Mitsubishi Electric released advisories and recommended mitigation strategies.
Why this matters for defenders
The disclosure of these vulnerabilities highlights the importance of timely patch management and network monitoring. Organizations relying on Mitsubishi Electric's MELSEC iQ-F Series modules must prioritize updating to fixed versions or implementing recommended workarounds to prevent potential service disruptions.
What remains unclear
While the vulnerabilities have been disclosed, specific details about potential exploit code are not publicly available. Further technical analysis may be required to fully understand the scope and impact of these vulnerabilities on different system configurations.
Defender guidance
For CVE-2026-8805:
- Update: Apply the latest firmware update provided by Mitsubishi Electric.
- Workaround: Implement network controls to limit TCP connection requests to the FX5-EIP module.
For CVE-2026-8806:
- Workaround: Configure network devices to filter excessive communication packets directed at the FX5-ENET/IP module.
- Monitor: Use IDS with rules tailored to detect anomalies related to these vulnerabilities.
Organizations should refer to Mitsubishi Electric's official advisories for detailed mitigation steps and updates.
