VORANT. Threat Intelligence Sign in Get the full feed

Mitsubishi MELSEC Ethernet module DoS flaw unfixable

medium vulnerability manufacturing

A DoS vulnerability in Mitsubishi Electric's MELSEC iQ-F FX5-ENET/IP Ethernet Module allows remote attackers to crash communications via packet flooding, with no fix planned.

Mitsubishi Electric has disclosed CVE-2026-8806, an Expected Behavior Violation vulnerability in the MELSEC iQ-F Series FX5-ENET/IP Ethernet Module affecting all versions. A remote attacker can trigger a denial-of-service condition by flooding the Ethernet port with a large volume of packets in a short timeframe, overloading the module's processing capacity and preventing internal anomaly-detection mechanisms from functioning, ultimately causing the communication function to stop.

Notably, Mitsubishi Electric has announced no plans to release a fix for this vulnerability. Instead, the vendor recommends compensating controls including network segmentation (restricting the module to LAN-only operation), deploying firewalls and VPNs to block unauthorized access, using the module's built-in IP filter function to whitelist trusted hosts, restricting physical access to affected systems, and installing anti-virus software on connected PCs.

This advisory affects critical manufacturing environments worldwide where the FX5-ENET/IP module is deployed. Organizations using this hardware must rely entirely on defense-in-depth measures to mitigate the risk, as no patch will be forthcoming.

Mentioned in this report

Vulnerabilities CVE-2026-8806

Detection guidance

Potential Flood/DoS Traffic Directed at MELSEC iQ-F FX5-ENET/IP Module Ports

ATT&CK T1498

Detects network traffic to the well-known MELSEC iQ-F FX5-ENET/IP communication ports originating from outside the expected engineering/OT subnet, which may indicate reconnaissance or a precursor to a flooding-based DoS attack against the unpatched CVE-2026-8806 vulnerability; a genuine flood should be corroborated with a high connection/packet-rate alert from network monitoring tooling over a short time window. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

title: Network Traffic to MELSEC iQ-F Ethernet Module from Untrusted Source
id: be040c24-0518-53fe-a277-6eed69f13f97
status: experimental
description: 'Identifies TCP/UDP connections to ports commonly used by Mitsubishi
  Electric MELSEC iQ-F FX5-ENET/IP modules (e.g. 5006/5007 MC protocol, 502 Modbus/TCP)
  originating from hosts outside the defined OT/engineering network segment. CVE-2026-8806
  allows a remote attacker to crash the module''s communication function by flooding
  it with a large volume of packets in a short period; the vendor will not release
  a patch and recommends restricting access to the module to LAN-only trusted hosts.
  Traffic from unexpected external sources to these ports should be treated as a potential
  precursor to, or ongoing, denial-of-service activity and correlated with connection/packet-rate
  metrics from network monitoring for confirmation of an actual flood.

  '
references:
- https://www.cisa.gov/
author: Vorant
tags:
- attack.t1498
logsource:
  category: network_connection
  product: network
detection:
  selection:
    dst_port:
    - 502
    - 5006
    - 5007
    - 5011
  filter:
    src_ip|cidr:
    - 10.0.0.0/8
    - 172.16.0.0/12
    - 192.168.0.0/16
  condition: selection and not filter
falsepositives:
- Legitimate engineering workstations or SCADA/HMI systems on non-RFC1918 addressed
  but authorized management subnets that were not included in the filter list
- Newly provisioned OT assets communicating with the module before network documentation/filters
  are updated
level: medium

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-169-06

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free