CVE-2026-32925
7.8Fuji Electric / Hakko Electronics · V-SFT
A stack-based buffer overflow in V-SFT versions 6.2.10.0 and prior allows arbitrary code execution when a user opens a specially crafted V7 file.
Executive summary
A critical stack-based buffer overflow vulnerability in Fuji Electric V-SFT software enables remote attackers to achieve arbitrary code execution through malicious file processing.
Vulnerability
The application contains a stack-based buffer overflow within the VS6ComFile!CV7BaseMap::WriteV7DataToRom function. An unauthenticated attacker can trigger this vulnerability by enticing a user to open a crafted V7 file, leading to potential code execution in the context of the application.
Business impact
The exploitation of this vulnerability poses a severe risk to operational integrity, as arbitrary code execution allows an attacker to gain control over the affected system. With a CVSS score of 7.8, this flaw represents a high-severity risk that could lead to full system compromise, loss of sensitive engineering data, or disruption of industrial automation processes.
Remediation
Immediate Action: Update the V-SFT software to the version specified in the vendor security advisory to resolve the buffer overflow vulnerability.
Proactive Monitoring: Monitor workstation file access logs and endpoint security telemetry for unusual application behavior or suspicious file handling activity originating from the V-SFT software.
Compensating Controls: Implement strict file access policies and ensure that users do not open untrusted or unexpected project files from unknown sources, as this vulnerability requires user interaction.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for arbitrary code execution, organizations utilizing V-SFT must prioritize patching all instances to version 6.2.10.1 or higher as recommended by Fuji Electric. Security teams should ensure that all users are aware of the risks associated with opening files from unverified sources while the update deployment is finalized.