Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      CodeSOD: A Unique Way to Primary Key

      July 22, 2025

      BrowserStack launches Figma plugin for detecting accessibility issues in design phase

      July 22, 2025

      Parasoft brings agentic AI to service virtualization in latest release

      July 22, 2025

      Node.js vs. Python for Backend: 7 Reasons C-Level Leaders Choose Node.js Talent

      July 21, 2025

      The best CRM software with email marketing in 2025: Expert tested and reviewed

      July 22, 2025

      This multi-port car charger can power 4 gadgets at once – and it’s surprisingly cheap

      July 22, 2025

      I’m a wearables editor and here are the 7 Pixel Watch 4 rumors I’m most curious about

      July 22, 2025

      8 ways I quickly leveled up my Linux skills – and you can too

      July 22, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      The Intersection of Agile and Accessibility – A Series on Designing for Everyone

      July 22, 2025
      Recent

      The Intersection of Agile and Accessibility – A Series on Designing for Everyone

      July 22, 2025

      Zero Trust & Cybersecurity Mesh: Your Org’s Survival Guide

      July 22, 2025

      Execute Ping Commands and Get Back Structured Data in PHP

      July 22, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      A Tomb Raider composer has been jailed — His legacy overshadowed by $75k+ in loan fraud

      July 22, 2025
      Recent

      A Tomb Raider composer has been jailed — His legacy overshadowed by $75k+ in loan fraud

      July 22, 2025

      “I don’t think I changed his mind” — NVIDIA CEO comments on H20 AI GPU sales resuming in China following a meeting with President Trump

      July 22, 2025

      Galaxy Z Fold 7 review: Six years later — Samsung finally cracks the foldable code

      July 22, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Yokogawa Recorder Vulnerability Could Let Attackers Hijack Critical Industrial Systems

    Yokogawa Recorder Vulnerability Could Let Attackers Hijack Critical Industrial Systems

    April 21, 2025
    Yokogawa Recorder Vulnerability Could Let Attackers Hijack Critical Industrial Systems

    Yokogawa Recorder Vulnerability

    A high-severity vulnerability has been discovered in a range of industrial recorder and data acquisition systems produced by Yokogawa Electric Corporation, a Japan-based automation and measurement equipment manufacturer. This flaw has been identified as CVE-2025-1863 and is categorized under CWE-306: Missing Authentication for Critical Function.

    The issue carries a CVSS v4 base score of 9.3 and a CVSS v3.1 score of 9.8, highlighting the extreme risk it poses to affected systems.

    Overview of Yokogawa Vulnerability

    The vulnerability is linked to insecure default settings in Yokogawa’s recorder products. Specifically, authentication is disabled by default on several of these devices. This means that when the devices are connected to a network without any configuration changes, anyone with network access can gain full access to critical functions—including system settings and operational controls.

    Such unrestricted access allows an attacker to manipulate measured values, alter system settings, and potentially compromise the integrity of critical operations in sectors like manufacturing, energy, and agriculture.

    Affected Yokogawa Products

    The vulnerability affects a wide range of Yokogawa’s paperless recorders and data acquisition units. The following models and versions are impacted:

    • GX10 / GX20 / GP10 / GP20 Paperless Recorders: R5.04.01 and earlier
    • GM Data Acquisition System: R5.05.01 and earlier
    • DX1000 / DX2000 / DX1000N Paperless Recorders: R4.21 and earlier
    • FX1000 Paperless Recorders: R1.31 and earlier
    • μR10000 / μR20000 Chart Recorders: R1.51 and earlier
    • MW100 Data Acquisition Units: All versions
    • DX1000T / DX2000T Paperless Recorders: All versions
    • CX1000 / CX2000 Paperless Recorders: All versions

    These devices are commonly used in critical infrastructure environments worldwide, including industrial manufacturing facilities, energy plants, and food processing units.

    Vulnerability Impact

    According to the technical evaluation, the Yokogawa vulnerability can be exploited remotely and with low attack complexity. No authentication or user interaction is needed, making it an attractive target for cyber attackers. The ability to manipulate sensitive data and operational settings without proper access control could result in:

    • Incorrect measurements and faulty process outcomes
    • Data integrity compromise
    • Downtime in production lines
    • Safety hazards in automated environments

    The threat becomes even more critical due to the default-disabled authentication, which implies that unless a user has manually enabled access controls, their systems are likely exposed.

    Technical Analysis

    The Yokogawa vulnerability stems from the absence of an enforced authentication mechanism in the default configuration of affected devices. In systems where authentication is not manually activated, any user on the network can access all critical device functions, including:

    • Configuration of sensors and thresholds
    • Adjustment of logging parameters
    • Export and modification of stored data

    The CVSS v4 vector string for this vulnerability is:

    CVSS4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

    This reflects:

    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Confidentiality, Integrity, and Availability Impact: High

    The vulnerability was discovered and disclosed by Souvik Kandar from MicroSec (microsec.io) and was coordinated with the Cybersecurity and Infrastructure Security Agency (CISA).

    Yokogawa’s Mitigation Measures

    Yokogawa has issued guidance for all users of the affected products. Key recommendations include:

    1. Enable Authentication: Immediately activate the login function (authentication feature) on all affected devices if they are connected to a network.
    2. Change Default Passwords: After enabling authentication, update the default credentials to strong, unique passwords to prevent unauthorized access.
    3. Implement a Comprehensive Security Program: Yokogawa strongly recommends a complete security strategy that includes:
      • Patch management and regular firmware updates
      • Anti-virus deployment
      • Data backup and recovery plans
      • Network zoning and segmentation
      • System hardening
      • Application and device whitelisting
      • Proper firewall configuration

    The company also offers security risk assessments to help customers evaluate and improve their current security posture.

    Impacted Industries and Global Reach

    Given the widespread use of Yokogawa recorders in automation and critical systems, this Yokogawa vulnerability has implications across several sectors:

    • Critical Manufacturing: Automated production environments rely heavily on precise data logging and process control. Manipulation of recorder settings could lead to costly downtime or product defects.
    • Energy: In power plants and substations, these devices often monitor critical parameters. A security breach could result in operational disruption or even physical damage.
    • Food and Agriculture: Accurate recording of environmental data is essential for food safety and quality. An attacker could alter data to mask spoilage or unsafe conditions.

    The default disabled authentication presents a critical security gap that can be easily closed with proper configuration. However, the responsibility lies with users and system integrators to follow through with security best practices.

    Conclusion

    Industrial operators must not assume out-of-the-box configurations are secure, especially when deploying devices in critical environments.

    As threat actors increasingly target operational technology (OT) systems, proactive device hardening and security governance become non-negotiable. Addressing this vulnerability promptly will not only secure your systems but also ensure continuity, safety, and reliability in critical operations.

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleAhold Delhaize USA Confirms Data Stolen in 2024 Cyberattack
    Next Article Laravel Toaster Magic

    Related Posts

    Development

    GPT-5 is Coming: Revolutionizing Software Testing

    July 22, 2025
    Development

    Win the Accessibility Game: Combining AI with Human Judgment

    July 22, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    CVE-2025-48881 – Valtimo Object Management Configuration Information Disclosure

    Common Vulnerabilities and Exposures (CVEs)

    Simplifying Stream Handling with Laravel’s resource Method

    Development

    The Impact of AI on Compliance and Risk Management for Mainframe Environments

    Databases

    Reliably Detecting Third-Party Cookie Blocking In 2025

    Tech & Work

    Highlights

    CVE-2024-41169 – Apache Zeppelin Raft Server Protocol Unauthenticated Directory Disclosure

    July 12, 2025

    CVE ID : CVE-2024-41169

    Published : July 12, 2025, 5:15 p.m. | 1 hour, 27 minutes ago

    Description : The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server’s resources, including directories and files.

    This issue affects Apache Zeppelin: from 0.10.1 up to 0.12.0.

    Users are recommended to upgrade to version 0.12.0, which fixes the issue by removing the Cluster Interpreter.

    Severity: 0.0 | NA

    Visit the link for more details, such as CVSS details, affected products, timeline, and more…

    Distribution Release: ExTiX 25.7

    July 1, 2025

    CVE-2025-6123 – Code-projects Restaurant Order System SQL Injection Vulnerability

    June 16, 2025

    CVE-2025-7536 – Campcodes Sales and Inventory System SQL Injection Vulnerability

    July 13, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.