Published:2025/10/02 Last Updated:2025/10/02
JVNVU#97069449
Multiple vulnerabilities in multiple Keyence products
Overview
Multiple products provided by KEYENCE CORPORATION contain multiple vulnerabilities.
Products Affected
CVE-2025-58775
- KV STUDIO versions 12.23 and prior
- VT5-WX15/WX12 versions 7.11 and prior
- KV STUDIO versions 12.23 and prior
- VT STUDIO versions 8.53 and prior
Description
Multiple products provided by KEYENCE CORPORATION contain multiple vulnerabilities listed below.
- Stack-based buffer overflow (CWE-121)
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 8.4
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Base Score 7.8
- CVE-2025-58775, CVE-2025-58776
- Access of uninitialized pointer (CWE-824)
- CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 7.1
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Base Score 7.8
- CVE-2025-58777
- Buffer underflow (CWE-124)
- CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 7.1
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Base Score 7.8
- CVE-2025-61690
- Out-of-bounds read (CWE-125)
- CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 7.1
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Base Score 7.8
- CVE-2025-61691
- Use after free (CWE-416)
- CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 7.1
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Base Score 7.8
- CVE-2025-61692
Impact
If the product uses a specially crafted file, arbitrary code may be executed on the affected product.
Solution
Update the Software
Update the software to the latest version according to the information provided by the developer.
Vendor Status
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
Michael Heinzl reported this vulnerability to JPCERT/CC.
JPCERT/CC coordinated with the developer.
Other Information
JPCERT Alert |
|
JPCERT Reports |
|
CERT Advisory |
|
CPNI Advisory |
|
TRnotes |
|
CVE |
CVE-2025-58775 |
CVE-2025-58776 |
|
CVE-2025-58777 |
|
CVE-2025-61690 |
|
CVE-2025-61691 |
|
CVE-2025-61692 |
|
JVN iPedia |
|