Mitsubishi Electric fixed an improper input validation vulnerability in its MELSEC iQ-R Series, according to a report with CISA.
Successful exploitation of this remotely exploitable vulnerability, which Mitsubishi self-reported, could allow a remote unauthenticated attacker to cause a denial-of-service condition on a target product by sending specially crafted packets.
The following Mitsubishi Electric MELSEC iQ-R Series products suffer from the issue:
- RJ71EN71: Firmware version “65” and prior
- R04/08/16/32/120ENCPU: Network part firmware version “65” and prior
In the vulnerability, MELSEC iQ-R Series RJ71EN71 products with firmware versions prior to “65” and R04/08/16/32/120ENCPU products with Network firmware versions prior to “65” are vulnerable to improper input validation. A remote unauthenticated user could cause a denial-of-service condition on a target product by sending specially crafted packets. A system reset is required to recover from a denial-of-service condition.
CVE-2022-40265 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 8.6.
The product sees use mainly in the critical manufacturing sector, and on a global basis.
No known public exploits specifically target this vulnerability. However, an attacker with low skill level could leverage this low complexity vulnerability.
Mitsubishi Electric fixed the vulnerability in the following MELSEC iQ-R Series products:
- RJ71EN71: Update firmware version to “66” or later
- R04/08/16/32/120ENCPU: Update network part firmware version to “66” or later
Users should refer to the following product manual for instructions to update firmware: MELSEC iQ-R Module Configuration Manual “Firmware Update Function.”
Mitsubishi Electric recommends users take the following mitigation measures to minimize the risk of an unauthenticated user exploiting this vulnerability:
- Use a firewall, virtual private network (VPN), etc. to prevent unauthorized access when Internet access is required
- Use the product within a local area network (LAN)
- Block access from untrusted networks and hosts through firewalls
- Use the IP filter function to restrict the accessible IP addresses
For using the IP filter function, users should see MELSEC iQ-R Ethernet User’s Manual (Application) Security “IP filter.”
Users can refer to the Mitsubishi Electric advisory for further details.

