CVE-2025-53524
7.8Fuji Electric · Monitouch V-SFT-6
Fuji Electric Monitouch V-SFT-6 contains an out-of-bounds write vulnerability in project file processing, which may allow an attacker to execute arbitrary code.
Executive summary
A critical out-of-bounds write vulnerability in Fuji Electric Monitouch V-SFT-6 could allow remote attackers to achieve arbitrary code execution via malicious project files.
Vulnerability
This vulnerability, categorized as CWE-787, involves an out-of-bounds write flaw triggered during the parsing of specially crafted project files. The vulnerability requires user interaction and can be triggered by an unauthenticated attacker.
Business impact
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the application, potentially leading to a full system compromise. Given the CVSS score of 7.8, this poses a significant risk to operational integrity and data confidentiality within industrial environments where this software is deployed.
Remediation
Immediate Action: Update the Monitouch V-SFT-6 software to version 6.2.9.0 or newer to fully resolve the underlying out-of-bounds write vulnerability.
Proactive Monitoring: Review system and application access logs for unusual file processing activity or unexpected application crashes that may indicate exploitation attempts.
Compensating Controls: Restrict access to project file imports and ensure that project files are only sourced from trusted, authenticated origins to prevent the processing of malicious files.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this vulnerability, combined with the potential for code execution, requires immediate attention from security teams managing industrial control systems. Administrators should prioritize upgrading to version 6.2.9.0 immediately, as this is the only definitive way to eliminate the risk of exploitation.
More Fuji Electric CVEs
Sources
Originally found and disclosed by Rocco Calvi with TecSecurity working with Trend Micro Zero Day Initiative reported these vulnerabilities to CISA., per the CVE Program record.