IM
IronMonkey Threat Research

CVE-2025-66606 CRITICAL

Published: 2026-02-09 | Last Modified: 2026-03-05 | Status: Analyzed

Description

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly encode URLs. An attacker could tamper with web pages or execute malicious scripts. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04

Additional Descriptions (1)

Se ha encontrado una vulnerabilidad en FAST/TOOLS proporcionado por Yokogawa Electric Corporation. Este producto no codifica correctamente las URL. Un atacante podría manipular páginas web o ejecutar scripts maliciosos. Los productos y versiones afectados son los siguientes: FAST/TOOLS (Paquetes: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 a R10.04

CVSS Metrics

Base Score: 9.6 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionREQUIRED
ScopeCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 2.8

Impact Score: 6.0

Base Score: 2.1 (LOW)

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack VectorNETWORK
Attack ComplexityHIGH
Attack RequirementsNONE
Privileges RequiredNONE
User InteractionACTIVE
Vulnerability ConfidentialityLOW
Vulnerability IntegrityNONE
Vulnerability AvailabilityNONE
Subsequent ConfidentialityLOW
Subsequent IntegrityNONE
Subsequent AvailabilityNONE

Source: 7168b535-132a-4efe-a076-338f829b2eb9

Type: Secondary

Weaknesses

Source Type Description
7168b535-132a-4efe-a076-338f829b2eb9 Secondary
en CWE-86

Affected Products

Vendor Product Version Update Type
yokogawa fast\/tools * <built-in method update of dict object at 0x7e6110a55200> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:yokogawa:fast\/tools:*:*:*:*:*:*:*:*

References

Notification
Message here