CVE-2025-66601 Details
Description
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not specify MIME types. When an attacker performs a content sniffing attack, malicious scripts could be executed. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04
A vulnerability exists in Yokogawa Electric Corporation's FAST/TOOLS that allows for content sniffing attacks. The issue arises because the application does not specify MIME types, which could enable the execution of malicious scripts. This vulnerability affects FAST/TOOLS versions R9.01 through R10.04, specifically in the packages RVSVRN, UNSVRN, HMIWEB, FTEES, and HMIMOB.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://web-material3.yokogawa.com/1/39206/files/YSAR-26-0001-E.pdf | YokogawaGroup | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-358 | Improperly Implemented Security Check for Standard | YokogawaGroup |
Affected Products
| Product | Versions |
|---|---|
| yokogawa fast/tools | >= r9.01, <= r10.04 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | YokogawaGroup |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 5, 2026 | Initial Analysis | [email protected] |
| Feb 9, 2026 | New CVE Received | YokogawaGroup |