CVE-2025-7405: Mitsubishi Electric Corporation Melsec Iq-F Series FX5S-30mr/ds

High severity, CVSS 7.3. EPSS: 0.5% chance of exploitation in the next 30 days.

Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote unauthenticated attacker to read or write the device values of the product and stop the operation of the programs, since MODBUS/TCP in the products does not have authentication features.

Affected products

Published 2025-09-01. Last modified 2026-06-17.