CVE-2025-66607 PUBLISHED

Assigner: YokogawaGroup
Reserved: 05.12.2025 Published: 09.02.2026 Updated: 09.02.2026

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation.

The response header contains an insecure setting. Users could be redirected to malicious sites by an attacker.

The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.3

Product Status

Vendor Yokogawa Electric Corporation
Product FAST/TOOLS
Versions Default: unknown
  • affected from R9.01 to R10.04 (incl.)

References

Problem Types

  • CWE-358 CWE