CVE-2025-66606

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly encode URLs. An attacker could tamper with web pages or execute malicious scripts. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04
Configurations

Configuration 1 (hide)

cpe:2.3:a:yokogawa:fast\/tools:*:*:*:*:*:*:*:*

History

05 Mar 2026, 12:38

Type Values Removed Values Added
Summary
  • (es) Se ha encontrado una vulnerabilidad en FAST/TOOLS proporcionado por Yokogawa Electric Corporation. Este producto no codifica correctamente las URL. Un atacante podría manipular páginas web o ejecutar scripts maliciosos. Los productos y versiones afectados son los siguientes: FAST/TOOLS (Paquetes: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 a R10.04
References () https://web-material3.yokogawa.com/1/39206/files/YSAR-26-0001-E.pdf - () https://web-material3.yokogawa.com/1/39206/files/YSAR-26-0001-E.pdf - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.6
CPE cpe:2.3:a:yokogawa:fast\/tools:*:*:*:*:*:*:*:*
First Time Yokogawa fast\/tools
Yokogawa

09 Feb 2026, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-09 04:15

Updated : 2026-03-05 12:38


NVD link : CVE-2025-66606

Mitre link : CVE-2025-66606

CVE.ORG link : CVE-2025-66606


JSON object : View

Products Affected

yokogawa

  • fast\/tools
CWE
CWE-86

Improper Neutralization of Invalid Characters in Identifiers in Web Pages