CVE-2025-61856
7.8Fuji Electric Co., Ltd. · V-SFT
A stack-based buffer overflow in Fuji Electric V-SFT allows attackers to achieve arbitrary code execution or cause system crashes by providing a specially crafted file.
Executive summary
A critical stack-based buffer overflow in Fuji Electric V-SFT v6.2.7.0 and earlier poses a significant risk of arbitrary code execution through the processing of malicious files.
Vulnerability
The software suffers from a stack-based buffer overflow in the VS6ComFile!CV7BaseMap::WriteV7DataToRom function. An attacker can trigger this vulnerability by enticing a user to open a specially crafted V-SFT file, which does not require prior authentication to execute.
Business impact
The exploitation of this vulnerability allows for arbitrary code execution on the host machine, potentially leading to a complete compromise of the affected system. Given the CVSS score of 7.8, this represents a high-severity risk that could result in significant data loss, unauthorized access to industrial control configurations, and operational downtime.
Remediation
Immediate Action: Users must update V-SFT to the latest version provided by Fuji Electric or Hakko Electronics to patch the vulnerable function.
Proactive Monitoring: Security teams should monitor workstation logs for abnormal application termination events or unexpected process activity originating from V-SFT.
Compensating Controls: Restrict the opening of untrusted or externally sourced project files within the V-SFT environment until the software has been updated.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the severity of potential arbitrary code execution, administrators should prioritize the deployment of vendor-supplied patches across all instances of V-SFT. Users should exercise extreme caution when handling project files from unverified sources until the update is applied to prevent triggering the overflow.