CVE-2025-66607
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The response header contains an insecure setting. Users could be redirected to malicious sites by an attacker. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.18%
- CWE
- CWE-358
- Published
- 2026-02-09
- Last modified
- 2026-03-13
Affected products
- Yokogawa Electric Corporation FAST/TOOLS
Weakness type
Related vulnerabilities
- CVE-2026-46582 — A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path
- CVE-2026-65058 — Trezor Safe improper security check in on-device display
- CVE-2026-49783 — Secure Boot Security Feature Bypass Vulnerability
- CVE-2026-54431 — Improper Data Validation in liboauth2
- CVE-2026-12577 — DVP80ES3 Improperly Implemented Security Check for Standard vulnerability
- CVE-2026-48797 — Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication
- CVE-2026-42081 — free5GC: UE Security Capability bypass on NGAP PathSwitchRequest
- CVE-2026-42082 — free5GC: Missing Concurrent NAS SMC Validation During NGAP Handover