PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-66601 Yokogawa CVE debrief

CVE-2025-66601 affects Yokogawa FAST/TOOLS where the product does not specify MIME types. According to the advisory, if an attacker can trigger content sniffing, malicious scripts could execute. CISA published the advisory on 2026-02-10 as ICSA-26-041-01 and the supplied CVSS v3.1 vector rates the issue 6.5/Medium.

Vendor
Yokogawa
Product
FAST/TOOLS
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-02-10
Original CVE updated
2026-02-10
Advisory published
2026-02-10
Advisory updated
2026-02-10

Who should care

OT and ICS operators running Yokogawa FAST/TOOLS, especially teams that expose the product through browser-based workflows or manage web-facing deployments. Security, patch-management, and network segmentation teams should also review the advisory and remediation steps.

Technical summary

The source advisory states that FAST/TOOLS does not specify MIME types. In a content-sniffing scenario, the client can interpret content in a way that allows malicious scripts to execute. The supplied CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N, which aligns with a network-reachable issue that can affect confidentiality and integrity without impacting availability.

Defensive priority

Medium. Prioritize remediation for any exposed FAST/TOOLS deployment and any environment where browser handling of served content could be influenced by untrusted input.

Recommended defensive actions

  • Update to revision R10.04 and apply patch software CS_e12787, as Yokogawa recommends.
  • After applying the patch, apply R10.04 SP3.
  • Maintain a comprehensive security program that includes patch updates, antivirus software, backup and recovery solutions, zoning, hardening, whitelisting, and firewalls.
  • Use Yokogawa security risk assessment services or contact Yokogawa for deployment-specific guidance if needed.

Evidence notes

The supplied CSAF record for ICSA-26-041-01 says FAST/TOOLS does not specify MIME types and that malicious scripts could execute during a content sniffing attack. The record was published and modified on 2026-02-10 and includes revision history showing version 1 as the initial republication of YSAR-26-0001-E. The remediation section recommends R10.04, patch software CS_e12787, and then R10.04 SP3. No KEV entry is provided in the supplied corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-66601 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-66601

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-66601 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-66601

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-041-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-041-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.