CVE-2025-66604 Details
Description
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The library version could be displayed on the web page. This information could be exploited by an attacker for other attacks. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04
A vulnerability exists in Yokogawa FAST/TOOLS versions R9.01 to R10.04, within the packages RVSVRN, UNSVRN, HMIWEB, FTEES, and HMIMOB. The issue arises because the library version can be displayed on web pages, potentially allowing attackers to use this information for further attacks.
Users are advised to upgrade to FAST/TOOLS R10.04 SP3 and apply the patch software CS_e12787. For assistance, contact your local Yokogawa supporting office.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://web-material3.yokogawa.com/1/39206/files/YSAR-26-0001-E.pdf | YokogawaGroup | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-319 | Cleartext Transmission of Sensitive Information | YokogawaGroup |
Affected Products
| Product | Versions |
|---|---|
| yokogawa fast/tools | >= r9.01, <= r10.04 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | YokogawaGroup |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 5, 2026 | Initial Analysis | [email protected] |
| Feb 9, 2026 | New CVE Received | YokogawaGroup |