Input Validation Flaw in Mitsubishi Electric MELSEC iQ-R Series
CVE-2025-15080

8.8HIGH

What is CVE-2025-15080?

An input validation vulnerability in the Mitsubishi Electric MELSEC iQ-R Series (models R08PCPU, R16PCPU, R32PCPU, and R120PCPU) permits unauthorized entities to exploit the system. Attackers may read sensitive device data or segments of control programs, alter device data, and create a denial of service (DoS) condition by dispatching specially crafted packets with precise commands. This flaw underscores the importance of robust validation mechanisms to safeguard against unauthorized data access and operational disruption.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

MELSEC iQ-R Series R08PCPU Firmware versions "48" and prior

MELSEC iQ-R Series R120PCPU Firmware versions "48" and prior

MELSEC iQ-R Series R16PCPU Firmware versions "48" and prior

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.