Vulnerability record · CVE-2025-66678 · published 4 March 2026
CVE-2025-66678: Faintsnow hardware read \& write utility sql injection vulnerability
FFaintsnow · Hardware Read \& Write Utility
An issue in the HwRwDrv.sys component of Nil Hardware Editor Hardware Read & Write Utility v1.25.11.26 and earlier allows attackers to execute arbitrary read and write operations via a crafted request.
Description
An issue in the HwRwDrv.sys component of Nil Hardware Editor Hardware Read & Write Utility v1.25.11.26 and earlier allows attackers to execute arbitrary read and write operations via a crafted request.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/Faintsnow/HE | Broken Link |
| https://github.com/cwjchoi01/CVE-2025-66678 | ExploitThird Party Advisory |
Track CVE-2025-66678 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2025-66678), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.