CVE-2025-66606
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly encode URLs. An attacker could tamper with web pages or execute malicious scripts. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04
Scoring
- Severity
- LOW
- CVSS base score
- 2.1
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
- EPSS probability
- 0.23%
- CWE
- CWE-86
- Published
- 2026-02-09
- Last modified
- 2026-03-13
Affected products
- Yokogawa Electric Corporation FAST/TOOLS
Weakness type
Related vulnerabilities
- CVE-2026-71478 — league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes
- CVE-2026-28417 — Vim has OS Command Injection in netrw
- CVE-2025-20168 — Cisco Common Services Platform Collector Cross-Site Scripting Vulnerability
- CVE-2025-20167 — Cisco Common Services Platform Collector Cross-Site Scripting Vulnerability
- CVE-2025-20166 — Cisco Common Services Platform Collector Cross-Site Scripting Vulnerability
- CVE-2021-33158 — Improper neutralization in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225...
- CVE-2024-21864 — Improper neutralization in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version...
- CVE-2023-22840 — Improper neutralization in software for the Intel(R) oneVPL GPU software before version 22.6.5 may...