# CVE-2025-66608

## Summary

- **CVE ID:** CVE-2025-66608
- **Severity:** HIGH
- **CVSS Score:** 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-29
- **Published:** Feb 9, 2026
- **Last Modified:** Mar 13, 2026

## Description

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation.



This product does not
properly validate URLs. An attacker could send specially crafted requests to
steal files from the web server.



The
affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to
R10.04

## Affected Products

- Yokogawa Electric Corporation — FAST/TOOLS (R9.01)

## References

- [CNA](https://web-material3.yokogawa.com/1/39206/files/YSAR-26-0001-E.pdf)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.40%
- **EPSS Percentile:** 33.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._