# Mitsubishi Electric MELSEC iQ-F FX5-ENET/IP and FX5-EIP remote unauthenticated denial-of-service via UDP flood (CVE-2026-1874, CVE-2026-1875, CVE-2026-1876)

> Multiple remotely exploitable denial-of-service (DoS) vulnerabilities affect Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet modules and FX5-EIP EtherNet/IP modules. A remote, unauthenticated attacker can continuously send UDP packets to an exposed module, causing uncontrolled receive-buffer consumption or resource-exhaustion (CWE-670 / CWE-404) that forces the PLC network module into a DoS state from which a manual system reset is required to recover. CISA rated the flaws CVSS 4.0 8.7 (HIGH) in advisory ICSA-26-62-01; internet-facing industrial devices are the primary risk.

- **Published:** 2026-08-04T00:00:00Z
- **Last reviewed:** 2026-08-04T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1874
- **ID:** TL-2026-1874
- **Severity:** HIGH (CVSS 8.7)
- **Category:** ICS_SCADA
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 2 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-1874, CVE-2026-1875, CVE-2026-1876, CVE-2026-8806

## Description

The Mitsubishi Electric MELSEC iQ-F Series is a widely deployed programmable logic controller (PLC) family used across manufacturing, water/wastewater, energy, and critical infrastructure. Its FX5-ENET/IP Ethernet module and FX5-EIP EtherNet/IP module expose the ODVA Common Industrial Protocol (CIP) over EtherNet/IP, which uses UDP/TCP encapsulation on port 44818 and implicit I/O messaging on UDP port 2222. CISA advisory ICSA-26-62-01 (published 2026-03-03) and Mitsubishi Electric PSIRT advisory 2025-021 disclose three related DoS vulnerabilities that share a single, trivially automatable attack vector: a remote attacker sends a continuous stream of UDP packets to the module, which the device fails to handle correctly, leading to uncontrolled receive-buffer consumption or improper resource shutdown/release. Recovery from the resulting outage requires a manual system reset of the module; the PLC process under control is disrupted in the interim.

CVE-2026-1874 (CWE-670, Always-Incorrect Control Flow Implementation) affects the FX5-ENET/IP module, firmware versions 1.106 and prior. Continuous UDP packet reception consumes the receive buffer without bound until memory is exhausted, forcing a DoS. It is fixed in firmware version 1.107 or later. CVE-2026-1875 (CWE-404, Improper Resource Shutdown or Release) affects the FX5-EIP module, versions 1.000 and prior, fixed in version 1.001 or later. CVE-2026-1876 (CWE-404) affects all versions of the FX5-ENET/IP module; as of the JVN update of 2026-04-23 the vendor has stated no patched firmware is planned for this flaw, leaving only mitigations. A closely related fourth flaw, CVE-2026-8806 (CWE-440, Expected Behavior Violation) in the FX5-ENET/IP line, also has no fix planned; technical analysis describes a real-time scheduling starvation condition in which a high-priority EtherNet/IP protocol task preempts the lower-priority internal anomaly-detection task indefinitely (a priority-inversion scenario), after which the module's internal supervisor declares the communication function unhealthy and shuts it down. On a 100 Mbps link the ratio tips at roughly 40,000 packets/sec (~27 Mbps), easily achieved from a compromised HMI or engineering workstation.

All four CVEs score CVSS 4.0 8.7 (HIGH) with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N and CVSS 3.1 7.5 (HIGH) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The NVD-referenced CISA-ADP SSVC assessment rates exploitation as 'none' (no confirmed in-the-wild exploitation), automatable as 'yes', and technical impact as 'partial'. CVE-2026-1874 is NOT in the CISA Known Exploited Vulnerabilities (KEV) catalog as of the 2026-07-21 KEV update. No named threat actor has been publicly confirmed exploiting these specific CVEs; however, the adjacent ICS/OT threat landscape is directly relevant: the IRGC-affiliated CyberAv3ngers demonstrated the Unitronics internet-exposed-PLC attack playbook in AA23-335A, the FrostyGoop malware weaponized Modbus TCP/502 against 46,000+ exposed devices in Ukraine, and Forescout documented the Ramnit worm infecting legitimate Mitsubishi GX Works engineering-workstation executables. Defense therefore centers on asset exposure reduction, network segmentation, firmware patch management, and high-rate UDP/EtherNet/IP packet-rate detection.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1691.001 Command Message
- T0814 Denial of Service
- T0822 External Remote Services

## Sources

- [CISA ICS Advisory ICSA-26-62-01 (Mitsubishi Electric MELSEC iQ-F Series)](https://www.cisa.gov/news-events/ics-advisories/icsa-26-62-01)
- [Mitsubishi Electric PSIRT Security Advisory 2025-021](https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-021_en.pdf)
- [JVN#JVNVU93286687 (MELSEC iQ-F Series)](https://jvn.jp/vu/JVNVU93286687/)
- [NVD - CVE-2026-1874](https://nvd.nist.gov/vuln/detail/CVE-2026-1874)
- [NVD - CVE-2026-1875](https://nvd.nist.gov/vuln/detail/CVE-2026-1875)
- [NVD - CVE-2026-1876](https://nvd.nist.gov/vuln/detail/CVE-2026-1876)
- [NVD - CVE-2026-8806 (FX5-ENET/IP scheduling starvation)](https://nvd.nist.gov/vuln/detail/CVE-2026-8806)
- [System Weakness - How a Packet Flood Silences a PLC's Own Watchdog](https://systemweakness.com/how-a-packet-flood-silences-a-plcs-own-watchdog-9ea99c65173a)
- [ODVA EtherNet/IP Developers Guide](https://www.odva.org/wp-content/uploads/2020/05/PUB00213R0_EtherNetIP_Developers_Guide.pdf)
- [EtherNet/IP Encapsulation Protocol Explained](https://scadaprotocols.com/ethernet-ip-encapsulation-protocol-explained/)
- [CISA KEV Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)
- [CISA/NCSC AA23-335A - IRGC-affiliated cyber actors exploiting PLCs](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a)
- [Mitsubishi Electric FA Download Site (firmware)](https://www.mitsubishielectric.com/fa/download/index.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1874
