CVE-2023-2846: Mitsubishielectric FX3G-14mr/ds Firmware

Critical severity, CVSS 9.1. EPSS: 1.3% chance of exploitation in the next 30 days.

Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series main modules allows a remote unauthenticated attacker to cancel the password/keyword setting and login to the affected products by sending specially crafted packets.

Affected products

Published 2023-06-30. Last modified 2026-06-17.