# Mitsubishi Electric PLC Module Vulnerable to Denial-of-Service Attacks with No Patch Available


## The Threat


Mitsubishi Electric has disclosed a denial-of-service (DoS) vulnerability affecting its MELSEC iQ-F Series FX5-ENET/IP Ethernet Module—a programmable logic controller (PLC) network interface widely deployed across manufacturing facilities worldwide. The vulnerability (CVE-2026-8806) allows remote attackers to disable the module's communication function by flooding it with a high volume of network packets, effectively taking critical automation systems offline without authentication or user interaction.


The attack works by overwhelming the module's processing capacity. When an attacker sends a large number of communication packets to the Ethernet port in rapid succession, the increased computational load prevents the device's internal anomaly-detection system from functioning properly. This forces the communication function to stop, severing the connection between the PLC and its control network. For manufacturing environments relying on real-time automation, this disruption could halt production lines, interrupt quality control, or disable safety-critical systems.


What makes this vulnerability particularly concerning is that Mitsubishi Electric has announced it will not be releasing a patch. Instead, the vendor is recommending defensive network measures—firewalls, VPNs, IP filtering, and network segmentation. For organizations running legacy industrial control systems that may have been installed a decade or more ago, patching is often not an option; the equipment is "set and forget" infrastructure not designed for frequent updates.


## Severity and Impact


| Metric | Details |

|--------|---------|

| CVE Identifier | CVE-2026-8806 |

| Vulnerability Type | Expected Behavior Violation (CWE-440) |

| CVSS v3.1 Score | 7.5 (HIGH) |

| CVSS v4.0 Score | 8.7 (HIGH) |

| Attack Vector | Network |

| Attack Complexity | Low |

| Privileges Required | None |

| User Interaction | None |

| Scope | Unchanged |

| Confidentiality Impact | None |

| Integrity Impact | None |

| Availability Impact | High |

| Vector String (v3.1) | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |

| Patch Status | No fix planned |


## Affected Products


  • Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module
  • - FX5-ENET/IP (all firmware versions)

    - Status: Known affected


    The vulnerability affects all versions of the FX5-ENET/IP module across all firmware releases. Organizations running any version of this hardware are exposed. Given the long deployment cycles in manufacturing environments, affected systems may range from relatively recent installations to equipment deployed in the mid-2010s or earlier.


    ## Mitigations


    Since Mitsubishi Electric is not releasing a software patch, organizations must implement compensating controls to reduce the risk of exploitation:


    Network Segmentation & Access Control

  • Isolate the FX5-ENET/IP module within a segregated LAN and block external network access through firewalls and network access control lists
  • Restrict access to the module to only authorized hosts on trusted internal networks
  • Implement a VPN gateway if remote monitoring or management is required; never expose the module directly to the internet

  • Module-Level Filtering

  • Enable the IP Filter function built into the FX5-ENET/IP module (documented in section 13.1 of the MELSEC iQ-F FX5 User's Manual) to explicitly whitelist only authorized sources and deny all other traffic
  • Configure ingress filtering rules to block requests from untrusted or unknown IP ranges

  • Physical Security

  • Restrict physical access to the PLC module and to any PCs or network devices that can communicate with it
  • Prevent unauthorized tampering or network cable replacement that could enable an attacker to route malicious traffic to the module

  • Endpoint Protection

  • Deploy and maintain antivirus and endpoint detection and response (EDR) software on any PC or workstation that has network access to the affected device
  • This reduces the risk that compromised internal systems could be used to generate attack traffic against the module

  • Network Monitoring

  • Implement network traffic monitoring and alerting to detect anomalous packet floods targeting the module's Ethernet port
  • Monitor the module's communication function status and alert if it becomes unresponsive

  • ## References


  • Official Mitsubishi Electric Security Advisory: https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-003_en.pdf
  • MELSEC iQ-F FX5 User's Manual (Communication Features): https://www.mitsubishielectric.com/fa/download/index.html

  • ---


    ## HackWire Analysis


    The "no patch" response to CVE-2026-8806 is increasingly emblematic of a structural vulnerability in industrial control system security. Unlike consumer software or enterprise applications where security updates are routine, manufacturing equipment often operates in constrained environments where patching is operationally risky or technically infeasible. A firmware update to a PLC module can require production downtime, vendor validation, or compatibility testing that spans weeks or months. For many organizations, the business cost of deploying a patch exceeds the perceived risk of the vulnerability itself.


    This calculus creates a permanent installed base of unpatched critical infrastructure. The FX5-ENET/IP is not an obscure product—Mitsubishi Electric is a major global automation supplier, and this module is embedded in factories, power substations, water treatment facilities, and other critical systems worldwide. Each of these installations now faces a perpetual DoS threat that can only be mitigated through network defenses, not through a vendor-supplied fix.


    The vulnerability also exposes a secondary risk: many organizations running this equipment likely don't have comprehensive network monitoring or segmentation in place. Industrial networks were historically isolated from IT networks by physical air-gapping or simple DMZs. As manufacturers adopt Industry 4.0 practices—connecting production systems to cloud analytics, remote monitoring, and enterprise ERP systems—the threat surface expands. An attacker with access to a factory's corporate network could potentially reach the PLC segment and launch a DoS attack against critical automation hardware.


    Organizations running FX5-ENET/IP modules should immediately audit their network topology to confirm whether the modules are properly segmented from untrusted networks. IP filtering should be enabled as a mandatory control. For facilities relying on this equipment for production-critical or safety-critical functions, compensation through redundancy or fail-over systems should be considered. The absence of a vendor patch means this vulnerability will remain a fixture of the threat landscape for years to come.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)