CVE-2026-32929

7.8

Fuji Electric / Hakko Electronics · V-SFT

V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability that may lead to information disclosure when opening a crafted V7 file.

Executive summary

An out-of-bounds read vulnerability in Fuji Electric V-SFT software could allow an attacker to disclose sensitive information via a specially crafted file.

Vulnerability

This vulnerability is an out-of-bounds read (CWE-125) located in the VS6ComFile!get_macro_mem_COM function. It can be triggered by an unauthenticated user if they are coerced into opening a malicious V7 file.

Business impact

Successful exploitation of this vulnerability could result in the disclosure of sensitive memory contents, potentially leading to the leakage of critical configuration data or credentials stored within the application memory. Given the CVSS score of 7.8, this represents a high-severity risk that requires attention to prevent unauthorized data access and potential lateral movement within industrial environments.

Remediation

Immediate Action: Update the V-SFT software to the version specified in the vendor advisory to incorporate the necessary memory safety patches.

Proactive Monitoring: Monitor system logs for unexpected application crashes or errors when processing V7 files, as these may indicate attempts to trigger the out-of-bounds read condition.

Compensating Controls: Restrict the ability of users to open untrusted or externally sourced V7 files on systems where V-SFT is installed, and employ endpoint security software to scan files for potential anomalies.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations utilizing V-SFT should prioritize upgrading to the latest patched version provided by Fuji Electric or Hakko Electronics. Because this vulnerability involves memory safety, applying vendor-supplied updates is the only reliable way to eliminate the risk of information disclosure.

More Fuji Electric / Hakko Electronics CVEs

Sources