
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-66589 is an Out-of-bounds Read vulnerability (CWE-125) in AzeoTech DAQFactory release 20.7 (Build 2555), a data acquisition and HMI software used in industrial control systems. The flaw allows an attacker to cause the program to read data past the end of an allocated buffer during CTL file parsing, potentially leading to information disclosure or a system crash. It was publicly disclosed on December 11, 2025, via a CISA ICS advisory (ICSA-25-345-03), with Zero Day Initiative advisories published on December 19, 2025. The vulnerability carries a CVSS v3.1 score of 7.8 (High) per CISA and a CVSS v4.0 score of 8.4 (High) (CISA Advisory, Red Hat CVE).
The vulnerability is classified as CWE-125 (Out-of-bounds Read) and is triggered during the parsing of specially crafted .ctl project files in AzeoTech DAQFactory. An attacker who can supply a malicious .ctl file to a victim user can cause the application to read memory beyond the bounds of an allocated buffer, which may expose sensitive in-memory data or cause a crash. Exploitation requires user interaction — specifically, a user must open the malicious file — and does not require any privileges. Multiple ZDI advisories (ZDI-25-1156 through ZDI-25-1161, and ZDI-26-058) document this and related vulnerabilities in the same file-parsing code path (CISA Advisory, ZDI-25-1159).
Successful exploitation can result in disclosure of sensitive information from process memory or a denial-of-service condition via application crash. In combination with related vulnerabilities in the same advisory (e.g., out-of-bounds write, use-after-free), an attacker could potentially achieve arbitrary code execution in the context of the current user process. Given DAQFactory's role in industrial data acquisition and HMI environments within critical manufacturing sectors, exploitation could disrupt operational technology (OT) processes or expose sensitive process data (CISA Advisory).
Multiple proof-of-concept advisories are publicly available through the Zero Day Initiative (ZDI-25-1156, ZDI-25-1157, ZDI-25-1158, ZDI-25-1159, ZDI-25-1160, ZDI-25-1161, and ZDI-26-058), published December 19, 2025, and February 3, 2026. CISA has stated that no known public exploitation specifically targeting this vulnerability has been reported, and the vulnerability is not exploitable remotely. The EPSS score is approximately 0.014% (very low probability of near-term exploitation). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (CISA Advisory, ZDI-25-1161).
.ctl project file that contains malformed data structures designed to trigger an out-of-bounds read during parsing..ctl file to a user running a vulnerable version of DAQFactory (≤20.7 Build 2555)..ctl file within DAQFactory, triggering the vulnerable file-parsing code path..ctl files in DAQFactory project directories, especially in locations writable by non-admin users.DAQFactory.exe) crashing unexpectedly or generating access violation errors; unusual child processes spawned by the DAQFactory process.DAQFactory.exe; Dr. Watson or Windows Error Reporting logs indicating memory access violations during CTL file parsing..ctl file, which may indicate chained code execution exploitation (CISA Advisory).AzeoTech has released DAQFactory Release 21.1, which addresses CVE-2025-66589 and all related vulnerabilities in the advisory. Until patching is possible, CISA and AzeoTech recommend: (1) avoiding opening .ctl files from unknown or untrusted sources; (2) storing .ctl files in directories writable only by admin-level users; (3) operating in DAQFactory's "Safe Mode" when loading documents that have been outside of organizational control; (4) applying a document editing password to project files; and (5) isolating DAQFactory systems from the internet and business networks using firewalls and VPNs (CISA Advisory).
CISA published ICS Advisory ICSA-25-345-03 on December 11, 2025, and issued Update A on December 30, 2025, which refined the researcher acknowledgments and removed two duplicate CVEs. The vulnerabilities were reported to CISA by Michael Heinzl, Rocco Calvi (@TecR0c) of TecSecurity via Trend Zero Day Initiative, and Andrea Micalizzi (@rgod777) of Trend Zero Day Initiative. The Hawk-Eye threat intelligence blog included this CVE in its weekly threat landscape digest for Week 2 of 2026, indicating moderate community awareness (CISA Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."