Security1 distinct publisher2 min readPublished
CVE-2025-3511 lets a crafted UDP packet stall CC-Link IE TSN modules. Update D restates the fixed-version thresholds model by model, which is the reconciliation work that three earlier revisions did not force.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Count the entries and the affected list runs to 43 distinct model numbers [10]. The supplied text breaks off mid-entry on a further MELSEC iQ-F module, so the real count is at least 43 [9].
The breakdown carries the operational weight. Twenty-six CC-Link IE TSN remote I/O modules are listed at firmware 09 and below [4]. Four analog and digital converter modules sit at 07 and below [5]. Three FPGA modules appear at version 01 with no range operator at all [6]. Two CP620 communication LSIs are gated at 1.08J and two CP610 parts at 05 [7]. On the MELSEC iQ-R side, RJ71GN11-T2 is affected through 26, RJ71GN11-EIP through 10, RJ71GN11-SX through 05, and RJ71EN71 through 85 [8]. FX5-CCLGN-MS runs to 1.020 and FX5-ENET to 1.200 [9].
That is ten different version thresholds for one CVE [11]. A fleet rule written as "anything at or below 09" clears the remote I/O population and leaves the 60AD4 converters, the CP620 LSIs at 1.08J, RJ71EN71 at 85, and FX5-ENET at 1.200 sitting under the same defect. The numbering formats are not even comparable to each other: two-digit sequential builds, a letter-suffixed 1.08J, and dotted strings where 1.020 is lower than 1.200. An inventory query has to compare per family, by part number, as text.
The FPGA modules deserve a separate look. They are listed at a single version, 01, rather than a range [6], and the supplied advisory text does not indicate whether a later build exists to move to [13]. That makes it a vendor question first and a change ticket second.
On urgency: the stated impact ceiling is availability. A specially crafted UDP packet can produce a denial of service, a timeout error, or a communication delay on the product [2]. There is no code execution claimed here, and the material at hand carries no CVSS score and no statement that anyone has exploited this in the field [13]. On modules that carry field I/O, a timeout is still a process event, so it earns a scheduled window rather than an unplanned one.
Across four lettered revisions [12] of ICSA-25-128-03 [3], the finding has stayed constant while the affected-version list keeps growing. The mechanism has been the same UDP packet since first publication [2]. Anyone who read the original, checked their masters, and closed the item is holding a diff taken against a shorter inventory than the one CISA is publishing now [1].
Ranked by verification strength, evidence, and original report placement.
The advisory lists 26 CC-Link IE TSN Remote I/O modules affected at version 09 and below: NZ2GN2S1-32D, -32T, -32TE, -32DT, -32DTE; NZ2GN2B1-32D, -32T, -32TE, -32DT, -32DTE; NZ2GNCF1-32D, -32T; NZ2GNCE3-32D, -32DT; NZ2GN12A4-16D, -16DE; NZ2GN12A2-16T, -16TE; NZ2GN12A42-16DT, -16DTE; NZ2GN2S1-16D, -16T, -16TE; NZ2GN2B1-16D, -16T, -16TE.
CC-Link IE TSN Analog-Digital Converter modules NZ2GN2S-60AD4 and NZ2GN2B-60AD4 and Digital-Analog Converter modules NZ2GN2S-60DA4 and NZ2GN2B-60DA4 are affected at version 07 and below.
CC-Link IE TSN FPGA modules NZ2GN2S-D41P01, NZ2GN2S-D41D01 and NZ2GN2S-D41PD02 are listed at version 01, without a "less than or equal to" range operator.
CISA published "Mitsubishi Electric Multiple FA Products (Update D)", an ICS advisory covering CVE-2025-3511 across Mitsubishi Electric factory automation products.
Per the advisory summary, successful exploitation could allow a remote attacker to cause a denial-of-service condition, a timeout error, or a communication delay by sending a specially crafted UDP packet to the product.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 27, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
CISA's Ebyte advisory carries no fixed version, because the vendor stopped answering1 distinct publisher
security
ASE2000's IEC 104 client accepts a forged peer certificate through version 2.371 distinct publisher
security
Johnson Controls console holds passwords in cleartext memory, and the fix line names two versions1 distinct publisher
security
Siemens IoT2050 gateways ship a Node-RED interface that asks nobody for a password1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Authoritative primary advisory, thin technical record
The single source is the disclosing authority's own advisory, which is the strongest available evidence that the weakness exists and delineates its scope: a named CVE, a named weakness class (CWE-1284), a stated impact path (crafted UDP packet), and a per-model affected-version table. That authority carries the score well above the midpoint. It is held back because the supplied text has no CVSS score, no fixed-version or mitigation data, no exploitation-status statement, and is itself truncated mid-sentence in the Vulnerabilities section, and because two derived counts in the ledger diverge from the source text.
No remediation or exploitation signal
Nothing in the supplied material measures real-world uptake: there is no exploitation-observed statement, no patch or firmware-update deployment data, no scan or exposure counts, and no install-base figures. The only footprint statement is boilerplate advisory metadata (Critical Manufacturing, worldwide, Japan headquarters), which cannot be converted into an adoption or remediation measure without inference.
Slightly understated relative to the source
Framing is close to aligned and, if anything, conservative. The advisory itself claims only availability impact (DoS, timeout, communication delay) and makes no exploitation or severity claim, and the story headline and dek stay within that. The mild negative comes from the derived counts sitting under the supplied text: the ledger says at least 43 model numbers where 49 are enumerated, and ten version thresholds where eleven appear, so the reconciliation burden being described is larger than stated. Offsetting slightly, the dek calls these 'fixed-version thresholds' when the advisory lists affected-version ceilings and supplies no fixed versions at all.
Low distortion, single-channel disclosure
The only publisher is a government cybersecurity agency operating under a disclosure mandate, with no commercial product, pricing or market interest in the framing, which keeps incentive pressure low. The residual reflects that the advisory relays vendor-supplied scope and version data with no independent verification in the cluster, and the vendor has an interest in a narrow availability-only characterisation and in an advisory that lists affected ceilings without publishing severity scoring; a single-channel disclosure leaves that unchecked.
High source authority, no corroboration
Confidence is moderate. The facts that matter most (advisory existence, CVE, impact statement, per-model version ceilings) come straight from the authoritative issuer and are unlikely to be wrong. But the cluster has one publisher and one item, the supplied body is truncated, adoption and exploitation are entirely unmeasured, and two derived ledger claims are contested against the source text, which limits how firmly any conclusion beyond the advisory's own contents can be held.