---
id: CVE-2025-66586
title: >-
  In AzeoTech DAQFactory release 20.7 (Build 2555), an access of resource using
  incompatible type vulnerability can be exploited to cause memory corruption
  while parsing specially crafted .ctl files
summary: >-
  In AzeoTech DAQFactory release 20.7 (Build 2555), an access of resource using
  incompatible type vulnerability can be exploited to cause memory corruption
  while parsing specially crafted .ctl files. This could allow an attacker to
  execute…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-843
vendor: azeotech
product: daqfactory
affected:
  - daqfactory < 21.1
patched:
  - daqfactory 21.1
published: '2025-12-11'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-66586'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-345-03.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-25-345-03'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
epss: 0.00221
epssPercentile: 0.11572
ingestedAt: '2026-10-07T20:46:46.865Z'
---

## Overview

In AzeoTech DAQFactory release 20.7 (Build 2555), an access of resource using incompatible type vulnerability can be exploited to cause memory corruption while parsing specially crafted .ctl files. This could allow an attacker to execute code in the context of the current process.

## Affected

- `daqfactory < 21.1`

## Remediation

Upgrade past the affected range:

- `daqfactory 21.1`
