Junglewise Threat Intelligence

CVE-2026-12390: AzeoTech DAQFactory type confusion via .ctl files

CVE-2026-12390 · Severity: info · CVSS 8.4 · Published 2026-06-18

Technologies: Azeotech Daqfactory. Vendors: Azeotech.

Executive brief

AzeoTech DAQFactory, a software suite used for data acquisition and industrial automation, is vulnerable to a security flaw when processing specific project files. An attacker could trick a user into opening a malicious .ctl file, which could allow the attacker to take control of the system or disrupt industrial operations. This could lead to unauthorized access to sensitive manufacturing data or a complete shutdown of the monitoring equipment.

Technical details

A Type Confusion vulnerability (CWE-843) exists in AzeoTech DAQFactory versions 21.1 and prior. The flaw is triggered when the application processes a specially crafted .ctl file, leading to the access of resources using an incompatible type. This is a local attack vector requiring user interaction (UI:A), where a user must be persuaded to open the malicious file. Successful exploitation can result in arbitrary code execution with the privileges of the application. CISA recommends mitigations such as using 'Safe Mode' when loading untrusted documents and restricting write access to folders containing .ctl files, as no specific software patch was detailed in the initial advisory.

Affected products

  • AzeoTech DAQFactory 21.1 and prior

Timeline

  • 2026-06-18: disclosed
  • 2026-06-18: advisory: ICSA-26-169-02 published by CISA

References

Related threats