Fuji Electric V-SFT Out-of-Bounds Read Vulnerability in VS6ComFile!load_link_inf

Vulnerability

A vulnerability allowing out-of-bounds read has been identified in the V-SFT application by Fuji Electric, specifically in versions through 6.2.7.0. This vulnerability occurs in the VS6ComFile!load_link_inf function and can be triggered by opening specially crafted V-SFT files. The exploitation of this vulnerability may lead to unauthorized information disclosure, cause the application to crash (abnormal end or ABEND), and allow arbitrary code execution on the affected system.

Impact

Exploitation of this vulnerability could result in information disclosure, an abnormal application termination (ABEND), and arbitrary code execution on the affected system.

Remediation

Users are advised to update the software to the latest version. Improvement information for V-SFT version 6 is available on the Fuji Electric Monitouch website.

Added: Oct 10, 2025, 11:19 AM
Updated: Oct 10, 2025, 11:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.4
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.