JTEKT ELECTRONICS CORPORATION Vulnerabilities and Affected Products
Vulnerabilities associated with HMI ViewJet C-more series.
Products
Clear product- Screen Creator Advance 28 vulnerabilities
- Kostac PLC Programming Software (Former name: Koyo PLC Programming Software)6 vulnerabilities
- GC-A22W-CW4 vulnerabilities
- GC-A244 vulnerabilities
- GC-A24-M4 vulnerabilities
- GC-A24W-C(W)4 vulnerabilities
- GC-A254 vulnerabilities
- GC-A264 vulnerabilities
- GC-A26-J24 vulnerabilities
- GC-A26W-C(W)4 vulnerabilities
- GC-A27-C4 vulnerabilities
- GC-A28-C4 vulnerabilities
- HMI ViewJet C-more series4 vulnerabilities
- HMI GC-A2 series2 vulnerabilities
- Kostac PLC Programming Software2 vulnerabilities
- OnSinView22 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-26401MEDIUM | Weak encoding for password vulnerability exists in HMI ViewJet C-more series. If this vulnerability is exploited, authentication information may be obtained by a local authenticated attacker. CWE-261Apr 4, 2025 | CVSS6.5v3.0 | EPSS0.164% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-25061MEDIUM | Unintended proxy or intermediary ('Confused Deputy') issue exists in HMI ViewJet C-more series and HMI GC-A2 series, which may allow a remote unauthenticated attacker to use the product as an intermediary for FTP bounce attack. CWE-441Apr 4, 2025 | CVSS5.8v3.0 | EPSS0.429% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-24317MEDIUM | Allocation of resources without limits or throttling issue exists in HMI ViewJet C-more series and HMI GC-A2 series, which may allow a remote unauthenticated attacker to cause a denial-of-service (DoS) condition. CWE-770Apr 4, 2025 | CVSS5.3v3.0 | EPSS0.575% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-24310MEDIUM | Improper restriction of rendered UI layers or frames issue exists in HMI ViewJet C-more series, which may allow a remote unauthenticated attacker to trick the product user to perform operations on the product's web pages. CWE-1021Apr 4, 2025 | CVSS4.3v3.0 | EPSS0.331% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |