CVE-2025-61858
7.8Fuji Electric / Hakko Electronics · V-SFT
An out-of-bounds write vulnerability in V-SFT allows attackers to trigger arbitrary code execution or system crashes via maliciously crafted project files.
Executive summary
A critical out-of-bounds write vulnerability in Fuji Electric V-SFT software presents a severe risk of arbitrary code execution and system failure when processing specially crafted files.
Vulnerability
This vulnerability, identified as an out-of-bounds write (CWE-787) within the VS6ComFile component, is triggered when the application parses a malicious file. It requires no authentication to trigger, though it does depend on user interaction to open the file.
Business impact
Successful exploitation of this flaw can result in total system compromise, including the execution of arbitrary code with the privileges of the application user. Given the CVSS score of 7.8, this represents a high-risk scenario that could lead to unauthorized data access, operational disruption, and the potential for lateral movement within a production environment.
Remediation
Immediate Action: Users should immediately transition to the latest available version of V-SFT as provided by the official Fuji Electric support portal.
Proactive Monitoring: Security teams should monitor workstation and server logs for abnormal application termination (ABEND) events or unauthorized file access patterns related to project file processing.
Compensating Controls: Implement strict file access controls and utilize endpoint security solutions to scan project files for anomalies before they are opened by the V-SFT application.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The potential for arbitrary code execution necessitates immediate attention despite the requirement for user interaction. Administrators must ensure that all instances of V-SFT are updated to versions beyond v6.2.7.0 as soon as the vendor patch is deployed. Failure to remediate this vulnerability leaves systems exposed to significant risk if an attacker successfully lures a user into opening a malicious project file.