---
id: CVE-2025-66590
title: >-
  In AzeoTech DAQFactory release 20.7 (Build 2555), an out-of-bounds write
  vulnerability can be exploited by an attacker to cause the program to write
  data past the end of an allocated memory buffer
summary: >-
  In AzeoTech DAQFactory release 20.7 (Build 2555), an out-of-bounds write
  vulnerability can be exploited by an attacker to cause the program to write
  data past the end of an allocated memory buffer. This can lead to arbitrary
  code executi…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-787
vendor: azeotech
product: daqfactory
affected:
  - daqfactory < 21.1
patched:
  - daqfactory 21.1
published: '2025-12-11'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-66590'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-345-03.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-25-345-03'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
epss: 0.00383
epssPercentile: 0.30114
ingestedAt: '2026-10-07T20:46:46.866Z'
---

## Overview

In AzeoTech DAQFactory release 20.7 (Build 2555), an out-of-bounds write vulnerability can be exploited by an attacker to cause the program to write data past the end of an allocated memory buffer. This can lead to arbitrary code execution or a system crash.

## Affected

- `daqfactory < 21.1`

## Remediation

Upgrade past the affected range:

- `daqfactory 21.1`
