CVE-2025-50130
7.8Fuji Electric Co., Ltd. · V-SFT and TELLUS
A heap-based buffer overflow in VS6Sim within V-SFT and TELLUS allows arbitrary code execution when processing specially crafted V9 or X1 files.
Executive summary
A critical heap-based buffer overflow vulnerability in Fuji Electric V-SFT and TELLUS software permits arbitrary code execution through the processing of malicious files.
Vulnerability
The software contains a heap-based buffer overflow (CWE-122) in the VS6Sim.exe component. An attacker can achieve arbitrary code execution by tricking a user into opening a specially crafted V9 or X1 file.
Business impact
Successful exploitation of this vulnerability allows an attacker to execute arbitrary code with the privileges of the application user. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to full system compromise, data exfiltration, or the installation of malicious software within the operational environment.
Remediation
Immediate Action: Review the official Fuji Electric security advisories provided via JVN to determine if a patch is available for your specific deployment, and apply updates immediately upon release.
Proactive Monitoring: Monitor system logs for unexpected application crashes or anomalous behavior related to VS6Sim.exe, as these may indicate attempted exploitation.
Compensating Controls: Restrict user access to untrusted V9 or X1 files and ensure that the software is run with the minimum necessary privileges to limit the potential blast radius of a successful exploit.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability presents a significant risk to industrial and engineering workstations utilizing Fuji Electric software. Administrators should prioritize identifying all instances of the affected products within their environment and prepare for deployment of vendor-supplied patches. Until a patch is confirmed, enforcing strict file handling policies is essential to mitigate the risk of arbitrary code execution.