ICS/OT

Fuji Electric HMI Configurator Flaws Expose Industrial Organizations to Hacking

Fuji Electric has released patches and Japan’s JPCERT has informed organizations about the vulnerabilities. 

HMI vulnerabilities

Several vulnerabilities patched recently by Fuji Electric in its V-SFT product could be exploited by threat actors to gain access to the systems of industrial organizations.

Fuji Electric (Hakko Electronic) V-SFT is a configuration and development software for human-machine interfaces (HMIs). Organizations in the manufacturing and other industrial sectors use it to create and manage user interfaces for Fuji Electric’s Monitouch series HMIs, which are widely used around the world.

Cybersecurity researcher Michael Heinzl discovered that V-SFT is affected by several vulnerabilities, including ones that can lead to information disclosure or arbitrary code execution on the system running the software. 

An attacker would need to use social engineering to trick a V-SFT user at the targeted organization into opening a malicious project file, which results in arbitrary code execution with the victim’s privileges. This can allow the hacker to take control of the system, Heinzl told SecurityWeek

Heinzl has published his own advisories for each of the V-SFT vulnerabilities. 

“The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure,” the researcher explained.

Advertisement. Scroll to continue reading.

The Japanese electrical equipment company has released patches (version 6.2.9.0), and Japan’s JPCERT recently published an advisory to inform organizations about the vulnerabilities. 

However, JPCERT’s advisory contains little information on potential impact, and Fuji’s release notes do not appear to mention any security fixes. 

The researcher told SecurityWeek that it took the vendor roughly four months to release patches after being notified. A previous batch of V-SFT vulnerabilities found by Heinzl took approximately nine months to address. 

In total, more than 20 security holes discovered by Heinzl were patched by Fuji Electric in its HMI programmer in recent months. 

Learn More at SecurityWeek’s ICS Cybersecurity Conference
The leading global conference series for Operations, Control Systems and OT/IT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

October 27-30, 2025 | Atlanta
www.icscybersecurityconference.com

Related: ICS Patch Tuesday: Fixes Announced by Siemens, Schneider, Rockwell, ABB, Phoenix Contact

Related: Radiflow Unveils New OT Security Platform

Related: Many Attacks Aimed at EU Targeted OT, Says Cybersecurity Agency

Related Content

Vulnerabilities

The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass.

ICS/OT

Georgia has been confirmed as one of the attacked states after Clayton County reported a pump station disruption.

Network Security

Forescout researchers have found 15 new vulnerabilities in the TP-Link Omada networking ecosystem.

Artificial Intelligence

A crafted prompt to a low-privilege Google ADK agent could be used to pass a malicious hand-off comment to a privileged agent.

Vulnerabilities

Over 24,000 internet-accessible server-management interfaces disclose authentication hashes before login.

Vulnerabilities

The biggest single reward paid out by Microsoft between July 1, 2025, and June 30, 2026, was $200,000.

ICS/OT

The grants will help local governments assess and improve cyber defenses amid a multistate campaign targeting water and wastewater infrastructure.

Vulnerabilities

The N‑central vulnerability CVE-2026-18577 has been exploited in the wild after threat actors found a patch bypass.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version