CVE-2025-66586

In AzeoTech DAQFactory release 20.7 (Build 2555), an Access of Resource Using Incompatible Type vulnerability can be exploited to cause memory corruption while parsing specially crafted .ctl files. This could allow an attacker to execute code in the context of the current process.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-25-345-03 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

cpe:2.3:a:azeotech:daqfactory:*:*:*:*:*:*:*:*

History

02 Jan 2026, 20:06

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
References () https://www.cisa.gov/news-events/ics-advisories/icsa-25-345-03 - () https://www.cisa.gov/news-events/ics-advisories/icsa-25-345-03 - Third Party Advisory, US Government Resource
First Time Azeotech daqfactory
Azeotech
CPE cpe:2.3:a:azeotech:daqfactory:*:*:*:*:*:*:*:*

11 Dec 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-11 21:15

Updated : 2026-01-02 20:06


NVD link : CVE-2025-66586

Mitre link : CVE-2025-66586

CVE.ORG link : CVE-2025-66586


JSON object : View

Products Affected

azeotech

  • daqfactory
CWE
CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')