CVE-2026-12390

In AzeoTech DAQFactory versions 21.1 and prior, a Type Confusion vulnerability can be exploited by an attacker using specially crafted .ctl files which can result in code execution.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-26-169-02 US Government Resource Mitigation
Configurations

Configuration 1 (hide)

cpe:2.3:a:azeotech:daqfactory:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-18 19:16

Updated : 2026-07-15 15:25


NVD link : CVE-2026-12390

Mitre link : CVE-2026-12390

CVE.ORG link : CVE-2026-12390


JSON object : View

Products Affected

azeotech

  • daqfactory
CWE
CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')