# CVE-2025-66600

## Summary

- **CVE ID:** CVE-2025-66600
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-358
- **Published:** Feb 9, 2026
- **Last Modified:** Mar 13, 2026

## Description

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation.



This product lacks
HSTS (HTTP Strict Transport Security) configuration. When an attacker performs
a Man in the middle (MITM) attack, communications with the web server could be
sniffed.



The
affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to
R10.04

## Affected Products

- Yokogawa Electric Corporation — FAST/TOOLS (R9.01)

## References

- [CNA](https://web-material3.yokogawa.com/1/39206/files/YSAR-26-0001-E.pdf)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.32%
- **EPSS Percentile:** 24.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._