CVE-2026-1875

Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-EIP EtherNet/IP Module FX5-EIP versions 1.000 and prior allows a remote attacker to cause a denial-of-service (DoS) condition on the products by continuously sending UDP packets to the products. A system reset of the product is required for recovery.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:mitsubishielectric:melsec_iq-f_fx5-eip_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:melsec_iq-f_fx5-eip:*:*:*:*:*:*:*:*

History

30 Apr 2026, 19:26

Type Values Removed Values Added
CPE cpe:2.3:h:mitsubishielectric:melsec_iq-f_fx5-eip:*:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:melsec_iq-f_fx5-eip_firmware:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Mitsubishielectric melsec Iq-f Fx5-eip Firmware
Mitsubishielectric
Mitsubishielectric melsec Iq-f Fx5-eip
References () https://jvn.jp/vu/JVNVU93286687/ - () https://jvn.jp/vu/JVNVU93286687/ - Third Party Advisory
References () https://www.cisa.gov/news-events/ics-advisories/icsa-26-62-01 - () https://www.cisa.gov/news-events/ics-advisories/icsa-26-62-01 - Third Party Advisory
References () https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-021_en.pdf - () https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-021_en.pdf - Vendor Advisory

24 Apr 2026, 08:16

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de cierre o liberación inadecuados de recursos en Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-EIP EtherNet/IP Module FX5-EIP todas las versiones permite a un atacante remoto causar una condición de denegación de servicio (DoS) en los productos mediante el envío continuo de paquetes UDP a los productos. Se requiere un reinicio del sistema del producto para la recuperación.
Summary (en) Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-EIP EtherNet/IP Module FX5-EIP all versions allows a remote attacker to cause a denial-of-service (DoS) condition on the products by continuously sending UDP packets to the products. A system reset of the product is required for recovery. (en) Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-EIP EtherNet/IP Module FX5-EIP versions 1.000 and prior allows a remote attacker to cause a denial-of-service (DoS) condition on the products by continuously sending UDP packets to the products. A system reset of the product is required for recovery.

04 Mar 2026, 09:15

Type Values Removed Values Added
References
  • () https://www.cisa.gov/news-events/ics-advisories/icsa-26-62-01 -

03 Mar 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-03 07:16

Updated : 2026-04-30 19:26


NVD link : CVE-2026-1875

Mitre link : CVE-2026-1875

CVE.ORG link : CVE-2026-1875


JSON object : View

Products Affected

mitsubishielectric

  • melsec_iq-f_fx5-eip
  • melsec_iq-f_fx5-eip_firmware
CWE
CWE-404

Improper Resource Shutdown or Release