CVE-2025-5241: Denial-of-Service Vulnerability in MELSEC iQ-F Series

Published Jul 11, 2025
·
Updated

Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series allows a remote unauthenticated attacker to lockout legitimate users for a certain period by repeatedly attempting to login with incorrect passwords. The legitimate users will be unable to login until a certain period has passed after the lockout or until the product is reset.

Affected Software

74 affected components
Mitsubishi Electric MELSEC iQ-F Series
Mitsubishi Electric Corporation FX5U-32MT/ES
Mitsubishi Electric Corporation FX5U-32MT/DS
Mitsubishi Electric Corporation FX5U-32MT/ESS
Mitsubishi Electric Corporation FX5U-32MT/DSS
Mitsubishi Electric Corporation FX5U-32MR/ES
Mitsubishi Electric Corporation FX5U-32MR/DS
Mitsubishi Electric Corporation FX5U-64MT/ES
Mitsubishi Electric Corporation FX5U-64MT/DS
Mitsubishi Electric Corporation FX5U-64MT/ESS
Mitsubishi Electric Corporation FX5U-64MT/DSS
Mitsubishi Electric Corporation FX5U-64MR/ES
Mitsubishi Electric Corporation FX5U-64MR/DS
Mitsubishi Electric Corporation FX5U-80MT/ES
Mitsubishi Electric Corporation FX5U-80MT/DS
Mitsubishi Electric Corporation FX5U-80MT/ESS
Mitsubishi Electric Corporation FX5U-80MT/DSS
Mitsubishi Electric Corporation FX5U-80MR/ES
Mitsubishi Electric Corporation FX5U-80MR/DS
Mitsubishi Electric Corporation FX5UC-32MT/D
Mitsubishi Electric Corporation FX5UC-32MT/DSS
Mitsubishi Electric Corporation FX5UC-64MT/D
Mitsubishi Electric Corporation FX5UC-64MT/DSS
Mitsubishi Electric Corporation FX5UC-96MT/D
Mitsubishi Electric Corporation FX5UC-96MT/DSS
Mitsubishi Electric Corporation FX5UC-32MT/DS-TS
Mitsubishi Electric Corporation FX5UC-32MT/DSS-TS
Mitsubishi Electric Corporation FX5UC-32MR/DS-TS
Mitsubishi Electric Corporation FX5UJ-24MT/ES
Mitsubishi Electric Corporation FX5UJ-24MT/DS
Mitsubishi Electric Corporation FX5UJ-24MT/ESS
Mitsubishi Electric Corporation FX5UJ-24MT/DSS
Mitsubishi Electric Corporation FX5UJ-24MR/ES
Mitsubishi Electric Corporation FX5UJ-24MR/DS
Mitsubishi Electric Corporation FX5UJ-40MT/ES
Mitsubishi Electric Corporation FX5UJ-40MT/DS
Mitsubishi Electric Corporation FX5UJ-40MT/ESS
Mitsubishi Electric Corporation FX5UJ-40MT/DSS
Mitsubishi Electric Corporation FX5UJ-40MR/ES
Mitsubishi Electric Corporation FX5UJ-40MR/DS
Mitsubishi Electric Corporation FX5UJ-60MT/ES
Mitsubishi Electric Corporation FX5UJ-60MT/DS
Mitsubishi Electric Corporation FX5UJ-60MT/ESS
Mitsubishi Electric Corporation FX5UJ-60MT/DSS
Mitsubishi Electric Corporation FX5UJ-60MR/ES
Mitsubishi Electric Corporation FX5UJ-60MR/DS
Mitsubishi Electric Corporation FX5UJ-24MT/ES-A
Mitsubishi Electric Corporation FX5UJ-24MR/ES-A
Mitsubishi Electric Corporation FX5UJ-40MT/ES-A
Mitsubishi Electric Corporation FX5UJ-40MR/ES-A
Mitsubishi Electric Corporation FX5UJ-60MT/ES-A
Mitsubishi Electric Corporation FX5UJ-60MR/ES-A
Mitsubishi Electric Corporation FX5S-30MT/ES
Mitsubishi Electric Corporation FX5S-30MT/DS
Mitsubishi Electric Corporation FX5S-30MT/ESS
Mitsubishi Electric Corporation FX5S-30MT/DSS
Mitsubishi Electric Corporation FX5S-30MR/ES
Mitsubishi Electric Corporation FX5S-30MR/DS
Mitsubishi Electric Corporation FX5S-40MT/ES
Mitsubishi Electric Corporation FX5S-40MT/DS
Mitsubishi Electric Corporation FX5S-40MT/ESS
Mitsubishi Electric Corporation FX5S-40MT/DSS
Mitsubishi Electric Corporation FX5S-40MR/ES
Mitsubishi Electric Corporation FX5S-40MR/DS
Mitsubishi Electric Corporation FX5S-60MT/ES
Mitsubishi Electric Corporation FX5S-60MT/DS
Mitsubishi Electric Corporation FX5S-60MT/ESS
Mitsubishi Electric Corporation FX5S-60MT/DSS
Mitsubishi Electric Corporation FX5S-60MR/ES
Mitsubishi Electric Corporation FX5S-60MR/DS
Mitsubishi Electric Corporation FX5S-80MT/ES
Mitsubishi Electric Corporation FX5S-80MT/ESS
Mitsubishi Electric Corporation FX5S-80MR/ES
Mitsubishi Electric Corporation FX5-CCLGN-MS

Event History

Jul 11, 2025
CVE Published
via MITRE·12:16 AM
Data Sourced
via MITRE·12:16 AM
DescriptionSeverityWeakness
Data Sourced
via ICS·12:24 AM
SeverityWeaknessAffected Software
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeakness

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-5241?

CVE-2025-5241 has a severity rating that indicates a significant risk, allowing remote unauthenticated attackers to lockout legitimate users.

2

How do I fix CVE-2025-5241?

To fix CVE-2025-5241, update the affected firmware on your Mitsubishi Electric MELSEC iQ-F Series products as per the vendor's instructions.

3

Which products are affected by CVE-2025-5241?

CVE-2025-5241 affects multiple products in the Mitsubishi Electric MELSEC iQ-F Series, including FX5U and FX5UC models.

4

What type of attack is possible with CVE-2025-5241?

CVE-2025-5241 allows an attacker to execute a denial-of-service (DoS) attack by locking out legitimate users through repeated failed login attempts.

5

Is authentication required for exploiting CVE-2025-5241?

CVE-2025-5241 can be exploited by a remote unauthenticated attacker, making it particularly dangerous.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203