Home

Description

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly validate URLs. An attacker could send specially crafted requests to steal files from the web server. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04

PUBLISHED Reserved 2025-12-05 | Published 2026-02-09 | Updated 2026-02-09 | Assigner YokogawaGroup




HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-29

Product status

Default status
unknown

R9.01 (custom)
affected

References

web-material3.yokogawa.com/1/39206/files/YSAR-26-0001-E.pdf

cve.org (CVE-2025-66608)

nvd.nist.gov (CVE-2025-66608)

Download JSON