CVE-2025-54496
Severity CVSS v4.0:
HIGH
Type:
CWE-122
Heap-based Buffer Overflow
Publication date:
04/11/2025
Last modified:
12/11/2025
Description
A maliciously crafted project file may cause a heap-based buffer <br />
overflow in <br />
Fuji Electric Monitouch V-SFT-6, which may allow the attacker to execute arbitrary code.
Impact
Base Score 4.0
8.40
Severity 4.0
HIGH
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:fujielectric:monitouch_v-sft:*:*:*:*:*:*:*:* | 6.2.7.0 (including) | 6.2.9.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://felib.fujielectric.co.jp/en/document_search?tab=software&document1%5B1%5D=M10009&document2%5B1%5D=M20104&product1%5B1%5D=P10003&product2%5B1%5D=P20023&product3%5B1%5D=P30623&product4%5B1%5D=S11133&discontinued%5B1%5D=0&count=20&sort=en_title&page=1®ion=en-glb
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-308-01.json
- https://www.cisa.gov/news-events/ics-advisories/icsa-25-308-01



