← Vulnerability feed

Vulnerability record · CVE-2025-66608 · published 9 February 2026

CVE-2025-66608: Yokogawa fast\/tools vulnerability

Yokogawa · Fast\/Tools

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly validate URLs. An attacker could send specially crafted requests to steal files from the web server. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04

8.7 CVSS 4.0 High EPSS 0.40% · top 68.3% CWE-29 · CWE-29
8.7CVSS 4.0 base score
0.40%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly validate URLs. An attacker could send specially crafted requests to steal files from the web server. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-66608 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2025-66597Yokogawa fast\/tools broken cryptographic algorithm vulnerabilityA vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product supports weak cryptographic algorithms, potentia…EPSS 0.17%7.5CVE-2018-16196Yokogawa centum cs 3000 firmware improper input validation vulnerabilityMultiple Yokogawa products that contain Vnet/IP Open Communication Driver (CENTUM CS 3000(R3.05.00 - R3.09.50), CENTUM CS 3000 Entry Class(R3.05.00 -…EPSS 3.3%7.1CVE-2025-66598Yokogawa fast\/tools broken cryptographic algorithm vulnerabilityA vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product supports old SSL/TLS versions, potentially allow…EPSS 0.16%6.9CVE-2025-66596Yokogawa fast\/tools open redirect vulnerabilityA vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly validate request headers. When…EPSS 0.16%6.9CVE-2025-66594Yokogawa fast\/tools error message information leak vulnerabilityA vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. Detailed messages are displayed on the error page. This infor…EPSS 0.21%6.9CVE-2025-66602Yokogawa fast\/tools vulnerabilityA vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The web server accepts access by IP address. When a worm that…EPSS 0.31%6.3CVE-2025-66595Yokogawa fast\/tools cross-site request forgery vulnerabilityA vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product is vulnerable to Cross-Site Request Forgery (CSR…EPSS 0.10%6.3CVE-2025-66607Yokogawa fast\/tools vulnerabilityA vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The response header contains an insecure setting. Users could…EPSS 0.18%

Source: NIST National Vulnerability Database (record CVE-2025-66608), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.