CVE-2025-61861
7.8Fuji Electric / Hakko Electronics · V-SFT
An out-of-bounds read vulnerability in V-SFT software allows for information disclosure, system crashes, or arbitrary code execution via specially crafted files.
Executive summary
A critical out-of-bounds read vulnerability in Fuji Electric V-SFT software, rated at 7.8, poses a significant risk of arbitrary code execution and system failure if a user opens a malicious file.
Vulnerability
This is an out-of-bounds read flaw (CWE-125) occurring within the VS6ComFile component during the load_link_inf process. The vulnerability can be triggered by an unauthenticated attacker providing a specially crafted file to a user, which, when opened, executes with the privileges of that user.
Business impact
The potential for arbitrary code execution and system instability presents a high risk to operational continuity and data integrity. Given the CVSS score of 7.8, the ability for an attacker to compromise the local environment through a file-based vector necessitates immediate caution, especially in industrial control or engineering environments where V-SFT is deployed.
Remediation
Immediate Action: Users should immediately transition to the latest version of V-SFT as provided by the vendor and avoid opening untrusted or unexpected project files.
Proactive Monitoring: Security teams should monitor workstation logs for abnormal application termination events or suspicious file access patterns involving the V-SFT installation directory.
Compensating Controls: Implement strict file access controls and utilize endpoint detection and response (EDR) solutions to scan incoming project files for known malicious signatures before they are processed by the software.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability represents a significant security risk for users of the V-SFT platform. Organizations should prioritize updating their software to the latest version released by Fuji Electric. Until an update is applied, administrators must enforce strict policies regarding the handling of third-party project files to prevent accidental execution of malicious content.