IM
IronMonkey Threat Research
‹ Back to ICS Advisories

YSAR-25-0001: Insecure default settings for recorder products

CRITICAL
CVSS 9.8
Date 2026-07-28T15:24:00+00:00
Source yokogawa
Published by Yokogawa

// Description

1 / 2YSAR-25-0001-E Yokogawa Security Advisory Report > All Rights Reserved. Copyright © 2025, Yokogawa Electric Corporation # Yokogawa Security Advisory Report # YSAR-25-0001 Published on April 18, 2025 Last updated on May 26, 2025 ## YSAR-25-0001: Insecure default settings for recorder products Overview: Insecure default settings have been found in recorder products. Yokogawa has identified the range of affected products in this report. Please review the report and confirm w

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2025-1863 9.8 critical
Authentication is disabled by default on the affected products. When connected to a network with default settings, this could allow anyone to access all functions related to settings and operations. As a result, an attacker can illegally manipulate and configure important data such as measured values and settings.

// Remediations (6)

Mitigation: Be sure to change the password from the default setting after enabling the authentication function.
Be sure to change the password from the default setting after enabling the authentication function.
Mitigation: Yokogawa has provided the following countermeasures for this vulnerability:
Yokogawa has provided the following countermeasures for this vulnerability:
Mitigation: Yokogawa urges users to enable the authentication function when connecting the affected products to
Yokogawa urges users to enable the authentication function when connecting the affected products to the network (login function).
Mitigation: For more information and details on implementing these mitigations, users should see the Yokogawa ad
For more information and details on implementing these mitigations, users should see the Yokogawa advisory.
Mitigation: For more information, contact Yokogawa.
For more information, contact Yokogawa.
Mitigation: Yokogawa strongly recommends all users to establish and maintain a full security program. Security p
Yokogawa strongly recommends all users to establish and maintain a full security program. Security program components are patch updates, anti-virus, backup and recovery, zoning, hardening, whitelisting, firewall, etc. Yokogawa can assist in setting up and running the security program continuously. For considering the most effective risk mitigation plan, as a starting point, Yokogawa can perform a security risk assessment.

// References