CVE-2025-61860
7.8Fuji Electric Co., Ltd. / Hakko Electronics Co., Ltd. · V-SFT
An out-of-bounds read vulnerability in V-SFT allows attackers to cause information disclosure, system crashes, or arbitrary code execution via specially crafted files.
Executive summary
A critical out-of-bounds read vulnerability in Fuji Electric V-SFT versions 6.2.7.0 and earlier poses a significant risk of arbitrary code execution and system failure.
Vulnerability
This vulnerability is an out-of-bounds read error (CWE-125) occurring within the VS6MemInIF module. It can be triggered by an unauthenticated attacker if a user is induced to open a specially crafted V-SFT file.
Business impact
The potential for arbitrary code execution and system crashes (ABEND) represents a high risk to operational continuity and data integrity. Given the CVSS score of 7.8, this vulnerability is classified as High, indicating that successful exploitation could lead to full compromise of the application environment and unauthorized disclosure of sensitive information.
Remediation
Immediate Action: Users must update V-SFT to the latest version provided by the vendor to resolve the memory handling flaw.
Proactive Monitoring: Monitor system logs for unexpected application termination or abnormal memory usage patterns when processing project files.
Compensating Controls: Exercise extreme caution when opening V-SFT files from untrusted or unknown sources to prevent the malicious file from being parsed by the vulnerable application.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Organizations utilizing V-SFT should prioritize applying the vendor-supplied security updates as soon as they are available. Until systems are patched, administrators should restrict the processing of V-SFT files to trusted sources only and ensure that endpoint security controls are active to detect suspicious file-parsing activities.