This product does not
properly validate URLs. An attacker could send specially crafted requests to
steal files from the web server.
The
affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to
R10.04
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 09 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yokogawa
Yokogawa fast/tools |
|
| Vendors & Products |
Yokogawa
Yokogawa fast/tools |
Mon, 09 Feb 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly validate URLs. An attacker could send specially crafted requests to steal files from the web server. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04 | |
| Weaknesses | CWE-29 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: YokogawaGroup
Published:
Updated: 2026-02-09T19:06:39.777Z
Reserved: 2025-12-05T05:04:40.516Z
Link: CVE-2025-66608
Updated: 2026-02-09T19:04:15.271Z
Status : Awaiting Analysis
Published: 2026-02-09T04:15:50.203
Modified: 2026-02-09T16:08:35.290
Link: CVE-2025-66608
No data.
OpenCVE Enrichment
Updated: 2026-02-09T10:39:14Z