Mitsubishi Electric CNC Series Vulnerability CVE-2025-2399 - Out-of-Bounds Read Risk
CISA has issued an industrial control systems advisory (ICSA-26-078-05) disclosing CVE-2025-2399, a vulnerability in Mitsubishi Electric CNC Series (Update A) products. The issue stems from improper validation of specified index, position, or offset in input (CWE-1285). Successful exploitation could allow a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition. The vulnerability affects a wide range of Mitsubishi Electric CNC controllers including M800, M80, M700, M70, E, and C series models, with products deployed worldwide. Mitsubishi Electric has released vendor fixes requiring version updates (BC/FN/LK or later depending on model). Until patches are applied, the vendor recommends restricting access via firewall or VPN and operating affected devices within trusted LAN environments only.