Azeotech's vulnerability footprint concentrates in DAQFactory, an industrial data-acquisition and SCADA-adjacent platform that serves automation and monitoring deployments where memory safety and data integrity are critical. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code; the recurring weakness classes—including buffer-boundary violations, type confusion, uninitialized pointer access, cleartext credential transmission, and unsafe deserialization—reflect the low-level memory and protocol handling demands of real-time industrial software. Defenders should treat DAQFactory instances, especially internet-reachable or mission-critical deployments, as patching priorities; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Azeotech over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-3492HIGH Stack-based buffer overflow in Azeotech DAQFactory 5.85 build 1853 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a crafted | Sep 16, 2011 | 10.0 | 83 | NO | YES |
CVE-2011-2956HIGH AzeoTech DAQFactory before 5.85 (Build 1842) does not perform authentication for certain signals, which allows remote attackers to cause a denial of service (system reboot or shutd | Jul 28, 2011 | 7.8 | 35 | NO | YES |
CVE-2026-12390HIGH In AzeoTech DAQFactory versions 21.1 and prior, a Type Confusion vulnerability can be exploited by an attacker using specially crafted .ctl files which can result in code execution | Jun 18, 2026 | 7.8 | 33 | NO | NO |
CVE-2025-66588CRITICAL In AzeoTech DAQFactory release 20.7 (Build 2555), an access of uninitialized pointer vulnerability can be exploited by an attacker which can lead to arbitrary code execution. | Dec 11, 2025 | 9.8 | 33 | NO | NO |
CVE-2026-12921HIGH In AzeoTech DAQFactory versions 21.1 and prior, a Use After Free vulnerability can be exploited by an attacker using specially crafted .ctl files which can result in code execution | Jun 25, 2026 | 7.8 | 32 | NO | NO |
CVE-2025-66589CRITICAL In AzeoTech DAQFactory release 20.7 (Build 2555), an Out-of-bounds Read vulnerability can be exploited by an attacker to cause the program to read data past the end of an allocated | Dec 11, 2025 | 9.1 | 32 | NO | NO |
CVE-2025-66590CRITICAL In AzeoTech DAQFactory release 20.7 (Build 2555), an out-of-bounds write vulnerability can be exploited by an attacker to cause the program to write data past the end of an allocat | Dec 11, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-66586HIGH In AzeoTech DAQFactory release 20.7 (Build 2555), an access of resource using incompatible type vulnerability can be exploited to cause memory corruption while parsing specially cr | Dec 11, 2025 | 7.8 | 25 | NO | NO |
CVE-2025-66585HIGH In AzeoTech DAQFactory release 20.7 (Build 2555), a use after free vulnerability can be exploited to cause memory corruption while parsing specially crafted .ctl files. This could | Dec 11, 2025 | 7.8 | 25 | NO | NO |
CVE-2021-42543HIGH The affected application uses specific functions that could be abused through a crafted project file, which could lead to code execution, system reboot, and system shutdown. | Nov 5, 2021 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Azeotech.
Media articles that mention a CVE ID that affects a product developed by Azeotech — matched by CVE ID, not by vendor name.