CVE-2025-61862
7.8FUJI ELECTRIC CO., LTD. / Hakko Electronics Co., Ltd. · V-SFT
An out-of-bounds read vulnerability in the V-SFT v6 software may allow attackers to trigger information disclosure, application crashes, or arbitrary code execution via specially crafted files.
Executive summary
An out-of-bounds read vulnerability in FUJI ELECTRIC V-SFT v6.2.7.0 and earlier poses a critical risk of arbitrary code execution if a user opens a malicious file.
Vulnerability
The software contains an out-of-bounds read flaw within the VS6ComFile!get_ovlp_element_size function, which can be triggered by an unauthenticated user when opening a specially crafted file.
Business impact
Successful exploitation allows an attacker to achieve arbitrary code execution or cause an abnormal termination of the affected system. Given the CVSS score of 7.8, this vulnerability represents a high risk to operational integrity, potentially leading to unauthorized system control or significant service disruption in industrial control environments.
Remediation
Immediate Action: Review the official Fuji Electric Monitouch download portal for security updates and apply the latest version of V-SFT software to address this vulnerability.
Proactive Monitoring: Monitor system logs for unexpected application errors or crashes, particularly when handling external project files.
Compensating Controls: Restrict the opening of untrusted or externally sourced project files within the V-SFT environment to prevent the delivery of malicious payloads.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability presents a significant risk to systems utilizing V-SFT software. Organizations should prioritize updating to the latest secure version once available and enforce strict file handling policies to mitigate the risk of processing malicious files until a patch is fully implemented.