CVE-2025-15080
Information Disclosure, Information Tampering, and Denial of Service (DoS) Vulnerability in Mitsubishi Electric proprietary protocol communication and SLMP communication for FA products
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.8EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
05 Feb 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric MELSEC iQ-R Series R08PCPU, R16PCPU, R32PCPU, and R120PCPU allows an unauthenticated attacker to read device data or part of a control program from the affected product, write device data in the affected product, or cause a denial of service (DoS) condition on the affected product by sending a specially crafted packet containing a specific command to the affected product.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Mitsubishi Electric Corporation · MELSEC iQ-R Series R08PCPUMitsubishi Electric Corporation · MELSEC iQ-R Series R120PCPUMitsubishi Electric Corporation · MELSEC iQ-R Series R16PCPUMitsubishi Electric Corporation · MELSEC iQ-R Series R32PCPUWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →