← Vulnerability feed

Vulnerability record · CVE-2025-61858 · published 10 October 2025

CVE-2025-61858: Fujielectric monitouch v-sft out-of-bounds write vulnerability

FFujielectric · Monitouch V Sft

An out-of-bounds write vulnerability exists in VS6ComFile!set_AnimationItem of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.

8.4 CVSS 4.0 High EPSS 0.18% · top 93.2% CWE-787 · Out-of-bounds write
8.4CVSS 4.0 base score
0.18%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An out-of-bounds write vulnerability exists in VS6ComFile!set_AnimationItem of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-61858 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2017-9659Fujielectric monitouch v-sft memory buffer overflow vulnerabilityA Stack-Based Buffer Overflow issue was discovered in Fuji Electric Monitouch V-SFT versions prior to Version 5.4.43.0. The stack-based buffer overfl…EPSS 5.2%8.8CVE-2017-9660Fujielectric monitouch v-sft memory buffer overflow vulnerabilityA Heap-Based Buffer Overflow was discovered in Fuji Electric Monitouch V-SFT versions prior to Version 5.4.43.0. A heap-based buffer overflow vulnera…EPSS 5.1%8.5CVE-2024-5597Fujielectric monitouch v-sft type confusion vulnerabilityFuji Electric Monitouch V-SFT is vulnerable to a type confusion, which could cause a crash or code execution.EPSS 0.51%8.5CVE-2024-34171Fujielectric monitouch v-sft stack-based buffer overflow vulnerabilityFuji Electric Monitouch V-SFT is vulnerable to a stack-based buffer overflow, which could allow an attacker to execute arbitrary code.EPSS 0.56%8.5CVE-2024-5271Fujielectric monitouch v-sft type confusion vulnerabilityFuji Electric Monitouch V-SFT is vulnerable to an out-of-bounds write because of a type confusion, which could result in arbitrary code execution.EPSS 0.38%8.4CVE-2025-54496Fujielectric monitouch v-sft heap-based buffer overflow vulnerabilityA maliciously crafted project file may cause a heap-based buffer overflow in Fuji Electric Monitouch V-SFT-6, which may allow the attacker to execute…EPSS 0.18%8.4CVE-2025-54526Fujielectric monitouch v-sft stack-based buffer overflow vulnerabilityFuji Electric Monitouch V-SFT-6 is vulnerable to a stack-based buffer overflow while processing a specially crafted project file, which may allow an …EPSS 0.18%8.4CVE-2025-61862Fujielectric monitouch v-sft out-of-bounds read vulnerabilityAn out-of-bounds read vulnerability exists in VS6ComFile!get_ovlp_element_size of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files m…EPSS 0.17%

Source: NIST National Vulnerability Database (record CVE-2025-61858), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.