7.8
/ 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Description
A use after free vulnerability exists in VS6ComFile!load_link_inf of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.
Basic Information
ID
CVE-2025-61864
Source
jpcert
Published
Oct 10, 2025 at 11:05
Affected Product
Vendor
FUJI ELECTRIC CO., LTD. / Hakko Electronics Co., Ltd.
Product
V-SFT
Version
v6.2.7.0 and earlier
Affected Versions
FUJI ELECTRIC CO., LTD. / Hakko Electronics Co., Ltd. V-SFT v6.2.7.0 and earlier