Mitsubishi MELSEC Ethernet module DoS flaw unfixable
A DoS vulnerability in Mitsubishi Electric's MELSEC iQ-F FX5-ENET/IP Ethernet Module allows remote attackers to crash communications via packet flooding, with no fix planned.
Mitsubishi Electric has disclosed CVE-2026-8806, an Expected Behavior Violation vulnerability in the MELSEC iQ-F Series FX5-ENET/IP Ethernet Module affecting all versions. A remote attacker can trigger a denial-of-service condition by flooding the Ethernet port with a large volume of packets in a short timeframe, overloading the module's processing capacity and preventing internal anomaly-detection mechanisms from functioning, ultimately causing the communication function to stop.
Notably, Mitsubishi Electric has announced no plans to release a fix for this vulnerability. Instead, the vendor recommends compensating controls including network segmentation (restricting the module to LAN-only operation), deploying firewalls and VPNs to block unauthorized access, using the module's built-in IP filter function to whitelist trusted hosts, restricting physical access to affected systems, and installing anti-virus software on connected PCs.
This advisory affects critical manufacturing environments worldwide where the FX5-ENET/IP module is deployed. Organizations using this hardware must rely entirely on defense-in-depth measures to mitigate the risk, as no patch will be forthcoming.
Mentioned in this report
Detection guidance
Potential Flood/DoS Traffic Directed at MELSEC iQ-F FX5-ENET/IP Module Ports
Detects network traffic to the well-known MELSEC iQ-F FX5-ENET/IP communication ports originating from outside the expected engineering/OT subnet, which may indicate reconnaissance or a precursor to a flooding-based DoS attack against the unpatched CVE-2026-8806 vulnerability; a genuine flood should be corroborated with a high connection/packet-rate alert from network monitoring tooling over a short time window. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.
title: Network Traffic to MELSEC iQ-F Ethernet Module from Untrusted Source
id: be040c24-0518-53fe-a277-6eed69f13f97
status: experimental
description: 'Identifies TCP/UDP connections to ports commonly used by Mitsubishi
Electric MELSEC iQ-F FX5-ENET/IP modules (e.g. 5006/5007 MC protocol, 502 Modbus/TCP)
originating from hosts outside the defined OT/engineering network segment. CVE-2026-8806
allows a remote attacker to crash the module''s communication function by flooding
it with a large volume of packets in a short period; the vendor will not release
a patch and recommends restricting access to the module to LAN-only trusted hosts.
Traffic from unexpected external sources to these ports should be treated as a potential
precursor to, or ongoing, denial-of-service activity and correlated with connection/packet-rate
metrics from network monitoring for confirmation of an actual flood.
'
references:
- https://www.cisa.gov/
author: Vorant
tags:
- attack.t1498
logsource:
category: network_connection
product: network
detection:
selection:
dst_port:
- 502
- 5006
- 5007
- 5011
filter:
src_ip|cidr:
- 10.0.0.0/8
- 172.16.0.0/12
- 192.168.0.0/16
condition: selection and not filter
falsepositives:
- Legitimate engineering workstations or SCADA/HMI systems on non-RFC1918 addressed
but authorized management subnets that were not included in the filter list
- Newly provisioned OT assets communicating with the module before network documentation/filters
are updated
level: medium
Behavioural rules are generated from public reporting — validate in your environment before deploying.
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-169-06
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free