PatchSiren cyber security CVE debrief
CVE-2025-53524 Fuji Electric CVE debrief
A high-severity out-of-bounds write vulnerability in Fuji Electric Monitouch V-SFT-6 allows arbitrary code execution when processing malicious project files. The vulnerability was disclosed by CISA on November 4, 2025, with an update on December 16, 2025 that added the CVE identifier. Fuji Electric has released patched versions V6.2.8.0 and later, with V6.2.9.0 recommended as the target update.
- Vendor
- Fuji Electric
- Product
- Monitouch V-SFT-6
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-11-04
- Original CVE updated
- 2025-12-16
- Advisory published
- 2025-11-04
- Advisory updated
- 2025-12-16
Who should care
Organizations operating Fuji Electric Monitouch HMI systems in manufacturing, energy, water treatment, and other industrial environments. OT security teams, plant engineers, and HMI operators responsible for maintaining safe and reliable industrial control system operations.
Technical summary
The vulnerability exists in Fuji Electric Monitouch V-SFT-6 HMI configuration software. An out-of-bounds write occurs during processing of specially crafted project files, which can be leveraged to achieve arbitrary code execution. The attack vector requires local access with user interaction (opening a malicious project file). The CVSS 3.1 vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H indicates high impacts to confidentiality, integrity, and availability when exploited.
Defensive priority
HIGH
Recommended defensive actions
- Update Fuji Electric Monitouch V-SFT-6 to version V6.2.9.0 or newer per vendor guidance
- Restrict access to project file directories to authorized personnel only
- Implement application whitelisting to prevent execution of unauthorized binaries
- Train operators to recognize and avoid social engineering attacks targeting HMI systems
- Apply defense-in-depth strategies for industrial control system environments per CISA guidance
Evidence notes
CISA ICS advisory ICSA-25-308-01 documents this vulnerability with CVSS 3.1 score 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). The advisory was initially published November 4, 2025 and updated December 16, 2025 to add CVE-2025-53524. Fuji Electric remediation guidance specifies V-SFT V6.2.8.0 as the initial fix, with V6.2.9.0 or newer recommended.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-53524 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-53524
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-53524 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-53524
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-308-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-308-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.