#VU111378 Stack-based buffer overflow in Smart Editor - CVE-2025-41388
Published: June 19, 2025 / Updated: June 20, 2025
Smart Editor
Fuji Electric
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error. A remote unauthenticated attacker can trick a victim to open a specially crafted TL5, V8 or X1 file, trigger stack-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Remediation
External links
- https://www.cisa.gov/news-events/ics-advisories/icsa-25-168-04
- https://www.zerodayinitiative.com/advisories/ZDI-25-402/
- https://www.zerodayinitiative.com/advisories/ZDI-25-403/
- https://www.zerodayinitiative.com/advisories/ZDI-25-404/
- https://www.zerodayinitiative.com/advisories/ZDI-25-405/
- https://www.zerodayinitiative.com/advisories/ZDI-25-399/
- https://www.zerodayinitiative.com/advisories/ZDI-25-413/