Skip to main content

Improper Neutralization of Invalid Characters in Identifiers in Web Pages

CVE-2025-66606

Severity Low
Score 2.1/10

Summary

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly encode URLs. An attacker could tamper with web pages or execute malicious scripts. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04

  • LOW
  • NETWORK
  • HIGH
  • CHANGED
  • REQUIRED
  • NONE
  • HIGH
  • HIGH

CWE-86 - Improper Neutralization of Invalid Characters in Identifiers in Web Pages

The software does not neutralize or incorrectly neutralizes invalid characters or byte sequences in the middle of tag names, URI schemes, and other identifiers.

References

Advisory Timeline

  • Published