PatchSiren cyber security CVE debrief
CVE-2025-15080 Mitsubishi Electric CVE debrief
CVE-2025-15080 is a critical, network-reachable vulnerability in Mitsubishi Electric MELSEC iQ-R Series R08/16/32/120PCPU firmware affecting proprietary protocol and SLMP communications. According to the CISA advisory republishing Mitsubishi Electric’s 2025-020 notice, a specially crafted packet with a specific command may let an attacker read device data or part of a control program, write device data, or cause denial of service. Mitsubishi Electric advises updating to firmware version 49 or later and applying network and physical access restrictions until remediation is complete.
- Vendor
- Mitsubishi Electric
- Product
- MELSEC iQ-R Series R08/16/32/120PCPU firmware
- CVSS
- CRITICAL 9.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-05
- Original CVE updated
- 2026-02-05
- Advisory published
- 2026-02-05
- Advisory updated
- 2026-02-05
Who should care
OT/ICS operators using MELSEC iQ-R controllers, PLC and automation engineers, plant network administrators, and security teams responsible for segmented industrial networks and firmware maintenance.
Technical summary
The advisory describes an information disclosure, information tampering, and denial-of-service issue in Mitsubishi Electric proprietary protocol communication and SLMP communication used by the affected MELSEC iQ-R firmware. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H, indicating unauthenticated network attackability with high integrity and availability impact. The vendor states fixed firmware is version 49 or later and recommends firewall/VPN controls, IP filtering, LAN-only use, and restricting physical access to the product and connected network.
Defensive priority
Immediate
Recommended defensive actions
- Identify all Mitsubishi Electric MELSEC iQ-R Series R08/16/32/120PCPU firmware deployments and confirm whether they are below version 49.
- Upgrade affected devices to firmware version 49 or later using Mitsubishi Electric’s documented firmware update procedure and download package.
- Restrict access from untrusted networks and hosts with firewalls, VPNs, and IP filtering; keep the product within a segmented LAN where possible.
- Limit physical access to the affected product and its connected LAN.
- Review Mitsubishi Electric’s advisory and CISA industrial control system recommended practices for deployment-specific hardening guidance.
- Coordinate with local Mitsubishi Electric support if you need update assistance or confirmation of affected product handling.
Evidence notes
Primary evidence comes from the CISA CSAF advisory for ICSA-26-036-02, published and modified on 2026-02-05. The advisory states the issue affects Mitsubishi Electric MELSEC iQ-R Series R08/16/32/120PCPU firmware and can expose device data or part of a control program, modify device data, or cause denial of service through a specially crafted packet. The source also provides the vendor remediation target of firmware version 49 or later and mitigation guidance using firewalls, VPNs, IP filters, LAN-only exposure, and restricted physical access. No KEV entry is supplied in the enrichment data.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-15080 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-15080
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-15080 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-15080
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-036-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-036-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.