CVE-2025-66608

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly validate URLs. An attacker could send specially crafted requests to steal files from the web server. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04
Configurations

Configuration 1 (hide)

cpe:2.3:a:yokogawa:fast\/tools:*:*:*:*:*:*:*:*

History

06 Mar 2026, 20:27

Type Values Removed Values Added
CPE cpe:2.3:a:yokogawa:fast\/tools:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Yokogawa fast\/tools
Yokogawa
References () https://web-material3.yokogawa.com/1/39206/files/YSAR-26-0001-E.pdf - () https://web-material3.yokogawa.com/1/39206/files/YSAR-26-0001-E.pdf - Vendor Advisory
Summary
  • (es) Se ha encontrado una vulnerabilidad en FAST/TOOLS proporcionado por Yokogawa Electric Corporation. Este producto no valida correctamente las URL. Un atacante podría enviar solicitudes especialmente diseñadas para robar archivos del servidor web. Los productos y versiones afectados son los siguientes: FAST/TOOLS (Paquetes: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 a R10.04

09 Feb 2026, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-09 04:15

Updated : 2026-03-06 20:27


NVD link : CVE-2025-66608

Mitre link : CVE-2025-66608

CVE.ORG link : CVE-2025-66608


JSON object : View

Products Affected

yokogawa

  • fast\/tools
CWE
CWE-29

Path Traversal: '\..\filename'