IM
IronMonkey Threat Research
‹ Back to ICS Advisories

YSAR-26-0001: Vulnerabilities in FAST/TOOLS and CI Server

HIGH
CVSS 8.2
Date 2026-07-28T15:23:57+00:00
Source yokogawa
Published by Yokogawa

// Description

1 / 5YSAR-26-0001-E Yokogawa Security Advisory Report > All Rights Reserved. Copyright © 2026, Yokogawa Electric Corporation # Yokogawa Security Advisory Report # YSAR-26-0001 Published on February 9, 2026 Last updated on June 23, 2026 ## YSAR-26-0001: Vulnerabilities in FAST/TOOLS and CI Server Overview: Vulnerabilities have been found in FAST/TOOLS and CI Server. Yokogawa has identified the range of affected products in this report. Please review the report and confirm which

// Vulnerabilities (15)

CVE ID CVSS Score Severity Description
CVE-2025-66606 8.2 high
This product does not properly encode URLs. An attacker could tamper with web pages or execute malicious scripts.
CVE-2025-66605 8.2 high
Since there are input fields on this web page with the autocomplete attribute enabled, the input content could be saved in the browser the user is using.
CVE-2025-66602 8.2 high
The web server accepts access by IP address. When a worm that randomly searches for IP addresses intrudes into the network, it could potentially be attacked by the worm.
CVE-2025-66603 8.2 high
The web server accepts the OPTIONS method. An attacker could potentially use this information to carry out other attacks.
CVE-2025-66595 8.2 high
This product is vulnerable to cross-site request forgery (CSRF). When a user accesses a link crafted by an attacker, the user's account could be compromised.
CVE-2025-66600 8.2 high
This product lacks HSTS (HTTP Strict Transport Security) configuration. When an attacker performs a Man in the middle (MITM) attack, communications with the web server could be sniffed.
CVE-2025-66607 8.2 high
The response header contains an insecure setting. Users could be redirected to malicious sites by an attacker.
CVE-2025-66608 8.2 high
This product fails to adequately validate URLs. An attacker could send maliciously crafted requests to gain unauthorized access to files on the web server.
CVE-2025-66601 8.2 high
This product does not specify MIME types. When an attacker performs a content sniffing attack, malicious scripts could be executed.
CVE-2025-66604 8.2 high
The library version could be displayed on the web page. This information could be exploited by an attacker for other attacks.
CVE-2025-66597 8.2 high
This product supports weak cryptographic algorithms, potentially allowing an attacker to decrypt communications with the web server.
CVE-2025-66596 8.2 high
No description available.
CVE-2025-66594 8.2 high
Detailed messages are displayed on the error page. This information could be exploited by an attacker for other attacks.
CVE-2025-66599 8.2 high
Physical paths could be displayed on web pages. This information could be exploited by an attacker for other attacks.
CVE-2025-66598 8.2 high
This product supports old SSL/TLS versions, potentially allowing an attacker to decrypt communications with the web server.

// Remediations (3)

Mitigation: Yokogawa strongly recommends that all users establish and maintain a comprehensive security program,
Yokogawa strongly recommends that all users establish and maintain a comprehensive security program, not just for addressing the vulnerability identified in this YSAR. Security program components include patch updates, antivirus software, backup and recovery solutions, zoning, hardening, whitelisting, firewalls, and other related measures. Yokogawa can assist organizations in setting up and continuously maintaining a security program. As a starting point for developing the most effective risk mitigation plan, Yokogawa offers security risk assessment services.
Mitigation: Yokogawa recommends users update to revision R10.04 and apply patch software (CS_e12787). After the
Yokogawa recommends users update to revision R10.04 and apply patch software (CS_e12787). After the patch is applied, users should apply R10.04 SP3.
Mitigation: For questions related to this report, please contact Yokogawa https://contact.yokogawa.com/cs/gw?c-i
For questions related to this report, please contact Yokogawa https://contact.yokogawa.com/cs/gw?c-id=000498.

// References