Junglewise Threat Intelligence

CVE-2026-12921: AzeoTech DAQFactory Use After Free in .ctl file parsing

CVE-2026-12921 · Severity: info · CVSS 8.4 · Published 2026-06-25

Technologies: Azeotech Daqfactory. Vendors: Azeotech.

Executive brief

AzeoTech DAQFactory, a software suite used for data acquisition and industrial automation, is vulnerable to a security flaw when processing project files. An attacker could trick a user into opening a specially crafted .ctl file, which could allow the attacker to take control of the system or execute unauthorized commands. This could lead to a complete loss of confidentiality and integrity on the workstation used to manage industrial processes.

Technical details

A Use After Free (CWE-416) vulnerability exists in AzeoTech DAQFactory versions 21.1 and prior. The flaw is triggered when the application improperly manages memory while parsing specially crafted .ctl files. An attacker can exploit this by convincing a user to open a malicious file, leading to memory corruption and potentially arbitrary code execution with the privileges of the application. While the NVD entry focuses on Use After Free, related CISA documentation also mentions Type Confusion (CWE-843) in the same version range. Mitigation strategies include operating in 'Safe Mode' when loading untrusted documents and restricting write access to folders containing .ctl files.

Affected products

  • AzeoTech DAQFactory 21.1 and prior

Timeline

  • 2026-06-18: advisory: Initial CISA ICS Advisory published
  • 2026-06-25: disclosed: CVE published to NVD dataset

References

Related threats