V-SFT v6.2.5.0 and earlier contains an issue with stack-based buffer overflow in VS6File!CTxSubFile::get_ProgramFile_name function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution.
References
| Link | Resource |
|---|---|
| https://jvn.jp/en/vu/JVNVU97228144/ | Third Party Advisory |
| https://monitouch.fujielectric.com/site/download-e/09vsft6_inf/Search.php | Release Notes Vendor Advisory |
Configurations
History
19 May 2025, 17:33
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:fujielectric:monitouch_v-sft:*:*:*:*:*:*:*:* | |
| CWE | CWE-787 | |
| References | () https://jvn.jp/en/vu/JVNVU97228144/ - Third Party Advisory | |
| References | () https://monitouch.fujielectric.com/site/download-e/09vsft6_inf/Search.php - Release Notes, Vendor Advisory | |
| First Time |
Fujielectric monitouch V-sft
Fujielectric |
19 May 2025, 13:35
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
19 May 2025, 08:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-05-19 08:15
Updated : 2025-05-19 17:33
NVD link : CVE-2025-47758
Mitre link : CVE-2025-47758
CVE.ORG link : CVE-2025-47758
JSON object : View
Products Affected
fujielectric
- monitouch_v-sft
