A critical out-of-bounds write vulnerability, tracked as CVE-2025-53524, has been identified in Fuji Electric Monitouch V-SFT software. The flaw exists in the parsing of V7 project files, where insufficient validation of user-supplied data can result in a write past the end of an allocated buffer or object. Successful exploitation requires user interaction, such as opening a malicious file or visiting a crafted web page, and can allow attackers to execute arbitrary code in the context of the current process. The vulnerability has been assigned a CVSS score of 7.8 to 8.4, indicating high severity, and affects multiple versions of the Monitouch V-SFT product line.
Fuji Electric has released an update to address this vulnerability, and users are strongly advised to apply the patch as soon as possible. The issue was reported to the vendor in July 2025 and publicly disclosed in December 2025 through coordinated advisories. Security researchers, including Rocco Calvi of TecSecurity, are credited with discovering the flaw. No evidence of remote exploitation without user interaction has been reported, but the vulnerability poses a significant risk to organizations using the affected software in industrial environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On December 17, 2025, CVE-2025-53524 was publicly disclosed through ZDI and other advisory channels, describing an out-of-bounds write in Fuji Electric Monitouch V-SFT/V-SFT-6 that could lead to arbitrary code execution when processing crafted project files. The issue was also referenced in CISA-related advisory material and public vulnerability databases.
Fuji Electric released a software update to address the Monitouch V-SFT file parsing out-of-bounds write vulnerability. The fix was available by the time of public disclosure.
The out-of-bounds write vulnerability later assigned CVE-2025-53524 was reported to Fuji Electric in July 2025. One advisory credits Rocco Calvi of TecSecurity with the report.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcezerodayinitiative.com
Open sourcezerodayinitiative.com
Open sourcezerodayinitiative.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.