Fuji Electric FRENIC-Loader 4 is vulnerable to a deserialization of untrusted data when importing a file through a specified window, which may allow an attacker to execute arbitrary code.

Subscriptions

Vendors Products
Fujielectric Subscribe
Frenic Loader Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-26637 Fuji Electric FRENIC-Loader 4 is vulnerable to a deserialization of untrusted data when importing a file through a specified window, which may allow an attacker to execute arbitrary code.
Fixes

Solution

Fuji Electric recommends users update to v1.4.0.1 or later https://felib.fujielectric.co.jp/en/M10009/M20029/document_detail/b2f23970-e560-4961-8013-fc72be43681a .


Workaround

No workaround given by the vendor.

History

Thu, 04 Sep 2025 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Fujielectric
Fujielectric frenic Loader
Vendors & Products Fujielectric
Fujielectric frenic Loader

Wed, 03 Sep 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 03 Sep 2025 19:45:00 +0000

Type Values Removed Values Added
Description Fuji Electric FRENIC-Loader 4 is vulnerable to a deserialization of untrusted data when importing a file through a specified window, which may allow an attacker to execute arbitrary code.
Title Fuji Electric FRENIC-Loader 4 Deserialization of Untrusted Data
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-09-03T20:38:21.773Z

Reserved: 2025-08-22T16:35:26.993Z

Link: CVE-2025-9365

cve-icon Vulnrichment

Updated: 2025-09-03T20:38:15.492Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-03T20:15:37.350

Modified: 2025-09-04T15:35:29.497

Link: CVE-2025-9365

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-09-04T13:12:20Z

Weaknesses