CVE-2025-66596

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly validate request headers. When an attacker inserts an invalid host header, users could be redirected to malicious sites. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04
Configurations

Configuration 1 (hide)

cpe:2.3:a:yokogawa:fast\/tools:*:*:*:*:*:*:*:*

History

06 Mar 2026, 20:28

Type Values Removed Values Added
First Time Yokogawa fast\/tools
Yokogawa
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CPE cpe:2.3:a:yokogawa:fast\/tools:*:*:*:*:*:*:*:*
Summary
  • (es) Se ha encontrado una vulnerabilidad en FAST/TOOLS proporcionado por Yokogawa Electric Corporation. Este producto no valida correctamente los encabezados de solicitud. Cuando un atacante inserta un encabezado de host no válido, los usuarios podrían ser redirigidos a sitios maliciosos. Los productos y versiones afectados son los siguientes: FAST/TOOLS (Paquetes: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 a R10.04
References () https://web-material3.yokogawa.com/1/39206/files/YSAR-26-0001-E.pdf - () https://web-material3.yokogawa.com/1/39206/files/YSAR-26-0001-E.pdf - Vendor Advisory

09 Feb 2026, 05:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-09 05:16

Updated : 2026-03-06 20:28


NVD link : CVE-2025-66596

Mitre link : CVE-2025-66596

CVE.ORG link : CVE-2025-66596


JSON object : View

Products Affected

yokogawa

  • fast\/tools
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')