Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-66606

Quick assessment

Affected
Yokogawa Electric Corporation FAST/TOOLS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Yokogawa FAST/TOOLS是日本横河电机(Yokogawa)公司的一个实时操作管理和可视化软件。 Yokogawa FAST/TOOLS R9.01版本至R10.04版本存在安全漏洞,该漏洞源于URL编码不当,攻击者可能篡改网页或执行恶意脚本。

AI Predicted 6.1 Difficulty: Easy EPSS 0.22% · P12

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-66606

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly encode URLs. An attacker could tamper with web pages or execute malicious scripts. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
Web页面标识中非法字符转义处理不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
Yokogawa FAST/TOOLS 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Yokogawa FAST/TOOLS是日本横河电机(Yokogawa)公司的一个实时操作管理和可视化软件。 Yokogawa FAST/TOOLS R9.01版本至R10.04版本存在安全漏洞,该漏洞源于URL编码不当,攻击者可能篡改网页或执行恶意脚本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Yokogawa Electric Corporation FAST/TOOLS R9.01 ~ R10.04 -

II. Public POCs for CVE-2025-66606

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-66606

登录查看更多情报信息。

Same Patch Batch · Yokogawa Electric Corporation · 2026-02-09 · 15 CVEs total

CVE-2025-66604 Yokogawa FAST/TOOLS 安全漏洞
CVE-2025-66601 Yokogawa FAST/TOOLS 安全漏洞
CVE-2025-66607 Yokogawa FAST/TOOLS 安全漏洞
CVE-2025-66608 Yokogawa FAST/TOOLS 安全漏洞
CVE-2025-66600 Yokogawa FAST/TOOLS 安全漏洞
CVE-2025-66602 Yokogawa FAST/TOOLS 安全漏洞
CVE-2025-66603 Yokogawa FAST/TOOLS 安全漏洞
CVE-2025-66599 Yokogawa FAST/TOOLS 安全漏洞
CVE-2025-66605 Yokogawa FAST/TOOLS 安全漏洞
CVE-2025-66594 Yokogawa FAST/TOOLS 安全漏洞
CVE-2025-66596 Yokogawa FAST/TOOLS 安全漏洞
CVE-2025-66598 Yokogawa FAST/TOOLS 安全漏洞
CVE-2025-66595 Yokogawa FAST/TOOLS 安全漏洞
CVE-2025-66597 Yokogawa FAST/TOOLS 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2025-66606

No comments yet


Leave a comment