Heap-Based Buffer Overflow Vulnerability in V-SFT and TELLUS by FUJI ELECTRIC
CVE-2025-50130

8.4HIGH

What is CVE-2025-50130?

A heap-based buffer overflow vulnerability exists in the VS6Sim.exe component of the V-SFT and TELLUS software provided by FUJI ELECTRIC. When users open specially crafted V9 or X1 files, it may allow an attacker to execute arbitrary code, potentially compromising the system. This vulnerability emphasizes the need for users to apply the latest security updates and be cautious of opening files from untrusted sources.

Affected Version(s)

TELLUS v4.0.20.0 and earlier

V-SFT-6 v6.2.5.0 and earlier

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-50130 : Heap-Based Buffer Overflow Vulnerability in V-SFT and TELLUS by FUJI ELECTRIC