CVE-2025-15080 - CVE House
Back to Database
Status published High CVE-2025-15080

Information Disclosure, Information Tampering, and Denial of Service (DoS) Vulnerability in Mitsubishi Electric proprietary protocol communication and SLMP communication for FA products

Vulnerability Description

Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric MELSEC iQ-R Series R08PCPU, R16PCPU, R32PCPU, and R120PCPU allows an unauthenticated attacker to read device data or part of a control program from the affected product, write device data in the affected product, or cause a denial of service (DoS) condition on the affected product by sending a specially crafted packet containing a specific command to the affected product.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-15080

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Mitsubishi Electric Corporation

View all reports →

Affected Software

MELSEC iQ-R Series R08PCPU, MELSEC iQ-R Series R16PCPU, MELSEC iQ-R Series R32PCPU, MELSEC iQ-R Series R120PCPU
Vulnerable Versions:
Firmware versions "48" and prior

Timeline

Official Publish: February 5th, 2026
Last Modified: February 6th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.