PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-54496 Fuji Electric CVE debrief

A heap-based buffer overflow vulnerability exists in Fuji Electric Monitouch V-SFT-6, where a maliciously crafted project file can trigger arbitrary code execution. The vulnerability was initially disclosed on November 4, 2025, and subsequently updated on December 16, 2025 (Update A), which added CVE-2025-53524 to the advisory. Fuji Electric has released a patched version (V6.2.9.0 or newer) to address this issue. The CVSS 3.1 score of 7.8 reflects high impact on confidentiality, integrity, and availability, with local attack vector and user interaction required.

Vendor
Fuji Electric
Product
Monitouch V-SFT-6
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2025-11-04
Original CVE updated
2025-12-16
Advisory published
2025-11-04
Advisory updated
2025-12-16

Who should care

Organizations operating Fuji Electric Monitouch HMI systems in industrial environments, particularly those using V-SFT-6 for project development. Critical infrastructure operators, manufacturing facilities, and OT security teams should prioritize patching due to the potential for arbitrary code execution leading to operational disruption or safety impacts.

Technical summary

The vulnerability stems from improper handling of maliciously crafted project files in Fuji Electric Monitouch V-SFT-6, resulting in a heap-based buffer overflow. Successful exploitation requires local access and user interaction (opening a malicious file), but can lead to complete compromise of confidentiality, integrity, and availability on the affected system. The attack vector is local with low attack complexity, requiring no privileges but user interaction through the UI.

Defensive priority

HIGH

Recommended defensive actions

  • Update Fuji Electric Monitouch V-SFT-6 to version V6.2.9.0 or newer as provided in the October release.
  • Apply defense-in-depth strategies for industrial control systems, including network segmentation and access controls.
  • Implement user awareness training to recognize and avoid social engineering attacks, particularly phishing attempts involving unsolicited project files.
  • Do not click web links or open attachments in unsolicited email messages.
  • Refer to CISA guidance on recognizing and avoiding email scams and social engineering attacks.

Evidence notes

Source: CISA CSAF advisory ICSA-25-308-01. Vendor confirmed: Fuji Electric. Remediation confirmed: V-SFT V6.2.8.0 (October release) with recommendation to update to V6.2.9.0 or newer.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-54496 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-54496

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-54496 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-54496

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-308-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-308-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.