CVE-2025-1863
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2025-1863: Insecure default settings on Yokogawa Electric Corporation's recorder products allow unauthorized access, affecting various models including GX10/GX20, GP10/GP20, DX1000/DX2000, FX1000, μR10000/μR20000, MW100, DX1000T/DX2000T, CX1000, and CX2000. The authentication function is disabled by default, enabling attackers to manipulate and configure important data such as measured values and settings when connected to a network. Versions R5.04.01 or earlier for some paperless recorders, R5.05.01 or earlier for the GM Data Acquisition System, and all versions for the MW100 are affected. Other models have no specified version limits.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.