CVE-2026-1875 is an Improper Resource Shutdown or Release vulnerability affecting all versions of Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP Modules. A remote, unauthenticated attacker can trigger a denial-of-service (DoS) condition by continuously sending UDP packets to the product, requiring a system reset for recovery. This vulnerability carries a high CVSSv4 score of 8.7, indicating a severe impact on availability with low attack complexity. While there are no known exploits, Metasploit modules, or ExploitDB entries, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.000CPE matchmatch criteria | cpe:2.3:o:mitsubishielectric:melsec_iq-f_fx5-eip_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.