---
id: CVE-2025-66589
title: >-
  In AzeoTech DAQFactory release 20.7 (Build 2555), an Out-of-bounds Read
  vulnerability can be exploited by an attacker to cause the program to read
  data past the end of an allocated buffer
summary: >-
  In AzeoTech DAQFactory release 20.7 (Build 2555), an Out-of-bounds Read
  vulnerability can be exploited by an attacker to cause the program to read
  data past the end of an allocated buffer. This could allow an attacker to
  disclose informa…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'
cwe:
  - CWE-125
vendor: azeotech
product: daqfactory
affected:
  - daqfactory < 21.1
patched:
  - daqfactory 21.1
published: '2025-12-11'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-66589'
references:
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-25-345-03'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
epss: 0.00354
epssPercentile: 0.26769
ingestedAt: '2026-09-30T23:29:32.484Z'
---

## Overview

In AzeoTech DAQFactory release 20.7 (Build 2555), an Out-of-bounds Read vulnerability can be exploited by an attacker to cause the program to read data past the end of an allocated buffer. This could allow an attacker to disclose information or cause a system crash.

## Affected

- `daqfactory < 21.1`

## Remediation

Upgrade past the affected range:

- `daqfactory 21.1`
