PatchSiren cyber security CVE debrief
CVE-2025-66601 Yokogawa CVE debrief
CVE-2025-66601 affects Yokogawa FAST/TOOLS where the product does not specify MIME types. According to the advisory, if an attacker can trigger content sniffing, malicious scripts could execute. CISA published the advisory on 2026-02-10 as ICSA-26-041-01 and the supplied CVSS v3.1 vector rates the issue 6.5/Medium.
- Vendor
- Yokogawa
- Product
- FAST/TOOLS
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-10
- Original CVE updated
- 2026-02-10
- Advisory published
- 2026-02-10
- Advisory updated
- 2026-02-10
Who should care
OT and ICS operators running Yokogawa FAST/TOOLS, especially teams that expose the product through browser-based workflows or manage web-facing deployments. Security, patch-management, and network segmentation teams should also review the advisory and remediation steps.
Technical summary
The source advisory states that FAST/TOOLS does not specify MIME types. In a content-sniffing scenario, the client can interpret content in a way that allows malicious scripts to execute. The supplied CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N, which aligns with a network-reachable issue that can affect confidentiality and integrity without impacting availability.
Defensive priority
Medium. Prioritize remediation for any exposed FAST/TOOLS deployment and any environment where browser handling of served content could be influenced by untrusted input.
Recommended defensive actions
- Update to revision R10.04 and apply patch software CS_e12787, as Yokogawa recommends.
- After applying the patch, apply R10.04 SP3.
- Maintain a comprehensive security program that includes patch updates, antivirus software, backup and recovery solutions, zoning, hardening, whitelisting, and firewalls.
- Use Yokogawa security risk assessment services or contact Yokogawa for deployment-specific guidance if needed.
Evidence notes
The supplied CSAF record for ICSA-26-041-01 says FAST/TOOLS does not specify MIME types and that malicious scripts could execute during a content sniffing attack. The record was published and modified on 2026-02-10 and includes revision history showing version 1 as the initial republication of YSAR-26-0001-E. The remediation section recommends R10.04, patch software CS_e12787, and then R10.04 SP3. No KEV entry is provided in the supplied corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-66601 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-66601
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-66601 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-66601
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-041-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-041-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.