Executive Summary
In November 2025, the Cybersecurity and Infrastructure Security Agency (CISA) released five Industrial Control Systems (ICS) Advisories highlighting significant vulnerabilities impacting multiple vendors: Fuji Electric, Survision, Delta Electronics, Radiometrics, and IDIS. These advisories detail newly identified security issues, including unencrypted communication, improper authentication, and exploitable flaws exposing critical industrial and manufacturing systems to potential attack vectors. While no active exploitation has been publicly reported yet, the disclosed vulnerabilities could allow remote attackers to gain unauthorized access, disrupt operations, or compromise sensitive operational technology environments if left unaddressed.
This incident underscores the ongoing and urgent need for proactive vulnerability management and timely patching within ICS environments. With an uptick in vulnerability disclosures and the rising convergence of IT and operational technology, threat actors continue to target unpatched systems in critical infrastructure, amplifying regulatory and business risk for operators in energy, manufacturing, and transportation sectors.
Why This Matters Now
With critical infrastructure increasingly targeted and vulnerability windows rapidly shrinking, timely awareness and mitigation of disclosed ICS weaknesses are essential to prevent disruptive cyberattacks. The current advisory alerts highlight how legacy industrial devices remain exposed, urging operators to remediate promptly before malicious actors can exploit these known gaps.
Attack Path Analysis
Attackers exploited unpatched vulnerabilities in exposed ICS systems to gain initial access. Post-compromise, they exploited privilege escalation flaws or leveraged weak service identities to attain higher-level permissions. Using these privileges, the attackers moved laterally across cloud and network segments, targeting internal workloads and services. Control was maintained via encrypted or covert C2 channels that bypassed standard security controls. Sensitive data was exfiltrated using allowed outbound channels or by blending in with legitimate flows. Ultimately, attackers could disrupt operations, manipulate ICS processes, or deploy ransomware to cause business impact.
Kill Chain Progression
Initial Compromise
Description
The threat actors exploited unpatched vulnerabilities in internet-exposed ICS devices or applications to gain unauthorized access.
Related CVEs
CVE-2025-54496
CVSS 7.8A heap-based buffer overflow in Fuji Electric Monitouch V-SFT-6 allows remote code execution via a crafted project file.
Affected Products:
Fuji Electric Monitouch V-SFT-6 – <= 6.2.7.0
Exploit Status:
no public exploitCVE-2025-54526
CVSS 7.8A stack-based buffer overflow in Fuji Electric Monitouch V-SFT-6 allows remote code execution via a crafted project file.
Affected Products:
Fuji Electric Monitouch V-SFT-6 – <= 6.2.7.0
Exploit Status:
no public exploitCVE-2025-58317
CVSS 7.8A stack-based buffer overflow in Delta Electronics CNCSoft-G2 allows remote code execution via a crafted file.
Affected Products:
Delta Electronics CNCSoft-G2 – <= 1.0.0.0
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Exploit Vulnerability in Industrial Control Systems
Exploitation of Remote Services
Manipulation of Control
Firmware
Unauthorized Command Message
Device Restart/Shutdown
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Addressing Newly-Identified Vulnerabilities
Control ID: 6.2.4
NIS2 Directive – Vulnerability Handling and Disclosure
Control ID: Art. 21(2)(d)
CISA ZTMM 2.0 – Continuous Vulnerability Assessment
Control ID: VULN.1.1
DORA – ICT Risk Management – Patch and Vulnerability Management
Control ID: Art. 8(2)(c)
NYDFS 23 NYCRR 500 – Cybersecurity Policy based on Risk Assessment
Control ID: 500.03
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Oil/Energy/Solar/Greentech
Critical ICS vulnerabilities in Fuji Electric, Delta Electronics systems expose energy infrastructure to exploitation requiring immediate patching and enhanced monitoring capabilities.
Utilities
Industrial control system advisories reveal significant risks to power grid operations through compromised monitoring and control systems enabling potential service disruptions.
Industrial Automation
Multiple ICS vendor vulnerabilities including CNCSoft-G2 and Monitouch V-SFT-6 create attack vectors for manufacturing process disruption and operational technology compromise.
Transportation
License plate recognition camera vulnerabilities and VizAir system flaws expose critical transportation monitoring infrastructure to unauthorized access and surveillance compromise.
Sources
- CISA Releases Five Industrial Control Systems Advisorieshttps://www.cisa.gov/news-events/alerts/2025/11/04/cisa-releases-five-industrial-control-systems-advisoriesVerified
- Critical flaws in Fuji Electric, Delta Electronics, Survision, Radiometrics, IDIS systems raise security concerns for industrial sectorhttps://industrialcyber.co/cisa/critical-flaws-in-fuji-electric-delta-electronics-survision-radiometrics-idis-systems-raise-security-concerns-for-industrial-sector/Verified
- CVE-2025-54526 - Exploits & Severity - Feedlyhttps://feedly.com/cve/CVE-2025-54526Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, workload isolation, encrypted traffic controls, and real-time detection would have significantly constrained the attacker’s ability to spread, exfiltrate, or impact critical ICS and cloud assets. Centralized visibility and enforced egress policies are critical to containing vulnerability exploitation and lateral attacker movement.
Control: Cloud Firewall (ACF)
Mitigation: Reduces external exposure and blocks unauthorized inbound traffic.
Control: Zero Trust Segmentation
Mitigation: Limits movement and access even after initial compromise.
Control: East-West Traffic Security
Mitigation: Detects and blocks unauthorized lateral movement.
Control: Threat Detection & Anomaly Response
Mitigation: Anomalous C2 patterns are detected and alerts generated.
Control: Egress Security & Policy Enforcement
Mitigation: Prevents unauthorized outbound data transfers.
Limits post-compromise blast radius and enables rapid response.
Impact at a Glance
Affected Business Functions
- Manufacturing Operations
- Process Control
Estimated downtime: 3 days
Estimated loss: $500,000
Potential exposure of sensitive operational data and control parameters.
Recommended Actions
Key Takeaways & Next Steps
- • Review and apply network segmentation and least-privilege policies to isolate ICS assets.
- • Deploy cloud-native firewalls and restrict exposure of critical systems to only approved sources and services.
- • Enforce east-west traffic controls and microsegmentation to contain lateral movement within cloud and ICS environments.
- • Enable continuous threat detection and anomaly response tools for rapid alerting on suspicious behaviors and C2 traffic.
- • Apply strict egress filtering and encryption visibility to prevent data exfiltration or unintended outbound communications.



