Security1 distinct publisher2 min readPublished
An updated CISA advisory puts CVE-2025-2399 on 18 Mitsubishi Electric CNC model designations. Seventeen of them have a fixed firmware build to chase. The C80 has none, at any version.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Version letters carry the whole audit here. In each of the three fix tracks, the last affected build sits one letter below the fixed one: BB becomes BC, FM becomes FN, LJ becomes LK [15]. A controller reporting BB is in scope and a controller reporting BC is out, so a pass that recorded "up to date" without writing down the two-letter code produced nothing usable.
Then the part numbers. Eighteen model designations resolve to sixteen distinct BND numbers, because M730VW and M720VW both carry BND-1015W000, and M730VS and M720VS both carry BND-1012W000 [14]. An asset inventory keyed on part number shows one row where the advisory shows two names. The version cutoff for each pair is the same LJ either way [4], so the collapse is survivable as long as nobody reads a missing model name as a missing exposure.
C80 (BND-2036W000) is the outlier. It is listed as affected at all versions [9] and it appears in none of the three vendor fix instructions [19]. That leaves it in the category Mitsubishi wrote the fallback guidance for: firewall or VPN where internet access is required, otherwise LAN-only operation with untrusted networks and hosts blocked [10].
What the advisory does not do is say what changed. The text carries the model list, the three remediation groups and the mitigations, with no revision history and no dates [16]. Anyone who cleared the original advisory has no delta to work from, which makes this a full comparison of all 18 entries rather than a scan for new lines.
On exploitability: the stated impact is an out-of-bounds read producing a denial-of-service condition [2], and the description names no authentication or privilege precondition, only crafted packets sent to TCP port 683 [18]. The impact statement stops at availability [17]. The process being denied is a cutting program on a machine tool, and these are worldwide-deployed critical manufacturing assets [12].
Filtering TCP 683 at the cell boundary reaches all 18 models with one change, and per the advisory it is the only control available for the C80 [10]. The firmware letters can be collected at the pace machines come free.
Ranked by verification strength, evidence, and original report placement.
CISA published an advisory titled "Mitsubishi Electric CNC Series (Update A)".
Successful exploitation of the vulnerability could allow a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition in the affected products.
The flaw is an Improper Validation of Specified Index, Position, or Offset in Input (CWE-1285) that allows a remote attacker to cause an out-of-bounds read by sending specially crafted packets to TCP port 683.
Affected products listed for CVE-2025-2399: M800VW (BND-2051W000) <=BB, M800VS (BND-2052W000) <=BB, M80V (BND-2053W000) <=BB, M80VW (BND-2054W000) <=BB, M800W (BND-2005W000) <=FM, M800S (BND-2006W000) <=FM, M80 (BND-2007W000) <=FM, M80W (BND-2008W000) <=FM, E80 (BND-2009W000) <=FM, C80 (BND-2036W000) all versions, M750VW (BND-1015W002) <=LJ, M730VW (BND-1015W000) <=LJ, M720VW (BND-1015W000) <=LJ, M750VS (BND-1012W002) <=LJ, M730VS (BND-1012W000) <=LJ, M720VS (BND-1012W000) <=LJ, M70V (BND-1018W000) <=LJ, E70 (BND-1022W000) <=LJ.
Mitsubishi Electric directs customers to apply fixed version BC or later for M800VW (BND-2051W000), M800VS (BND-2052W000), M80V (BND-2053W000) and M80VW (BND-2054W000).
Mitsubishi Electric directs customers to apply fixed version FN or later for M800W (BND-2005W000), M800S (BND-2006W000), M80 (BND-2007W000), M80W (BND-2008W000) and E80 (BND-2009W000).
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 27, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
CISA revises the Mitsubishi FA advisory a fourth time for one UDP denial-of-service bug1 distinct publisher
security
ASE2000's IEC 104 client accepts a forged peer certificate through version 2.371 distinct publisher
security
Johnson Controls console holds passwords in cleartext memory, and the fix line names two versions1 distinct publisher
security
Siemens IoT2050 gateways ship a Node-RED interface that asks nobody for a password1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary advisory with itemized part numbers and fixes
The whole cluster rests on one document, but it is the authoritative primary artifact: a CISA ICS advisory built from a vendor self-report, with per-model part numbers, explicit version ceilings, three named fixed-version tracks, the CWE class and the exact TCP port. That supports precise version and exposure triage. It is docked because there is no corroborating publisher, no populated severity metrics in the supplied text, and no revision history explaining the Update A delta.
No field adoption or exploitation data
The supplied advisory documents a disclosure and a vendor fix availability, but provides no installed-base figures, no count of internet-reachable port 683 endpoints, no patch-uptake data and no statement that exploitation has been observed. Deployment is described only as 'worldwide', which is not a measurable adoption signal, so this dimension cannot be scored without inference.
Claims track the advisory
The story's framing - CVE-2025-2399 across 18 model designations, 17 with a fixed build to chase and C80 with none at any version - is exactly what the advisory's tables state, and the impact is kept to availability rather than escalated to code execution. Nothing in the cluster asserts exploitation, urgency or severity beyond the source text, and nothing understates the C80 gap either.
Vendor-authored disclosure, vendor-gated fix channel
The advisory records that Mitsubishi Electric reported the vulnerability to CISA, so the affected-scope, fixed-version and mitigation text originates with the party whose products are affected - an incentive to frame impact narrowly and to keep remediation inside its own channel, since every fix entry routes customers to a Mitsubishi Electric representative. Publication through CISA and the explicit disclosure that C80 has no fix at any version pull the other way, which keeps this mid-range rather than high.
High-fidelity facts, single source, unmeasurable adoption
Confidence in the factual claims is high because they are transcribed and tallied from an authoritative primary advisory. It is held below the top band because the cluster has one publisher, the Update A delta is undocumented, severity metrics are empty as supplied, and the adoption dimension could not be measured at all.