Junglewise Threat Intelligence

CVE-2025-66586: AzeoTech DAQFactory type confusion in .ctl file parsing

CVE-2025-66586 · Severity: high · CVSS 7.8 · Published 2025-12-11

Technologies: Azeotech Daqfactory. Vendors: Azeotech.

Executive brief

AzeoTech DAQFactory, a software suite used for data acquisition and industrial automation, is vulnerable to a memory corruption flaw. An attacker can exploit this by tricking a user into opening a specially crafted .ctl project file. Successful exploitation could allow the attacker to take control of the system or disrupt industrial operations.

Technical details

A type confusion vulnerability (CWE-843) exists in AzeoTech DAQFactory release 20.7 (Build 2555) and earlier. The flaw occurs during the parsing of .ctl files when the application accesses a resource using an incompatible type, leading to memory corruption. An attacker can exploit this by providing a malicious .ctl file that, when opened by a user, triggers the vulnerability. This can result in arbitrary code execution in the context of the current process. The issue is resolved in DAQFactory Release 21.1.

Affected products

  • AzeoTech DAQFactory <= 20.7 Build 2555

Timeline

  • 2025-12-11: disclosed
  • 2025-12-11: advisory
  • 2025-12-30: other: Advisory updated by CISA

References

Related threats