Fuji Electric Monitouch V-SFT-6 human-machine interface (HMI) configuration software is affected by two critical vulnerabilities: a heap-based buffer overflow (CVE-2025-54496) and a stack-based buffer overflow (CVE-2025-54526). Both vulnerabilities can be triggered by processing specially crafted project files, potentially allowing attackers to execute arbitrary code on affected systems. The vulnerabilities impact at least version 6.2.7.0 of the software, and exploitation could result in device crashes or full compromise of the HMI environment. The vulnerabilities are rated with a CVSS v4 base score of 8.4, indicating high severity, and require user interaction to trigger, but do not require remote exploitation.
CISA has issued an advisory (ICSA-25-308-01) detailing these vulnerabilities and urging users and administrators to review technical details and apply recommended mitigations. The advisories emphasize the risk to industrial control environments and recommend caution when handling project files from untrusted sources. No specific affected product list has been published, but the vulnerabilities are confirmed in the latest available version. Organizations using Fuji Electric Monitouch V-SFT-6 should prioritize patching and follow CISA's mitigation guidance to reduce the risk of exploitation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Public vulnerability records for the two Fuji Electric Monitouch V-SFT-6 flaws were published, including severity information and remediation guidance. CVE-2025-54526 was described as a high-severity stack-based buffer overflow with no public exploit evidence at publication time.
CISA disclosed two critical vulnerabilities in Fuji Electric Monitouch V-SFT-6 HMI configuration software: a heap-based buffer overflow (CVE-2025-54496) and a stack-based buffer overflow (CVE-2025-54526). The agency said exploitation requires a user to process a malicious project file, provided mitigation guidance, and noted no public exploitation had been reported.
Fuji Electric addressed the vulnerabilities in Monitouch V-SFT-6 version 6.2.8.0 and recommended customers update to version 6.2.9.0 or later. The affected version identified in the advisory was 6.2.7.0.
Rocco Calvi of TecSecurity reported two vulnerabilities in Fuji Electric Monitouch V-SFT-6 to the vendor via Trend Micro Zero Day Initiative. The flaws were later assigned CVE-2025-54496 and CVE-2025-54526.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecisa.gov
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.