CVE-2025-5241 describes an Overly Restrictive Account Lockout Mechanism in Mitsubishi Electric Corporation MELSEC iQ-F Series, allowing a remote, unauthenticated attacker to temporarily lock out legitimate users through repeated incorrect login attempts. This medium severity vulnerability (CVSS 5.3) has a low impact, primarily causing denial of service (A:L) by preventing legitimate users from accessing the system until a timeout or reset. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Mitsubishi Electric Corporation | MELSEC IQ-F Series FX5-CCLGN-MS | All versionsCNA affecteddefault unaffected | |
| Mitsubishi Electric Corporation | MELSEC IQ-F Series FX5S-30MR/DS | All versionsCNA affecteddefault unaffected | |
| Mitsubishi Electric Corporation | MELSEC IQ-F Series FX5S-30MR/ES | All versionsCNA affecteddefault unaffected | |
| Mitsubishi Electric Corporation | MELSEC IQ-F Series FX5S-30MT/DS | All versionsCNA affecteddefault unaffected | |
| Mitsubishi Electric Corporation | MELSEC IQ-F Series FX5S-30MT/DSS | All versionsCNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.