# Type Confusion Flaw in AzeoTech DAQFactory Allows Arbitrary Code Execution on Industrial Systems


## The Threat


A critical type confusion vulnerability in AzeoTech DAQFactory threatens industrial control systems worldwide, allowing attackers to execute arbitrary code through specially crafted .ctl files. CVE-2026-12390 exploits a flaw in how the software handles data type validation, enabling an attacker to bypass security boundaries and gain full system control once a malicious file is opened.


The vulnerability is particularly dangerous because it requires minimal preconditions to exploit. An attacker simply needs to deliver a malicious .ctl (control) file to a target user—via email, compromised website, or supply chain vector. When the user opens the file, the type confusion flaw allows the attacker's code to execute with the same privileges as the user running DAQFactory. For systems running DAQFactory with administrative rights (common in industrial deployments), this translates to complete system compromise.


AzeoTech DAQFactory is widely deployed across critical manufacturing environments globally. The software is used for data acquisition, process monitoring, and automation in plants that manage everything from chemical production to pharmaceutical manufacturing. A vulnerability in this class of software could disrupt production lines, compromise safety systems, or expose sensitive operational data. The fact that the attack requires only user interaction—not network connectivity—makes it ideal for targeted attacks against specific industrial organizations.


## Severity and Impact


| Aspect | Details |

|--------|---------|

| CVE Identifier | CVE-2026-12390 |

| Vulnerability Type | Type Confusion (CWE-843: Access of Resource Using Incompatible Type) |

| CVSS 3.1 Score | 7.8 (HIGH) |

| CVSS 4.0 Score | 8.4 (HIGH) |

| Attack Vector | Local (AV:L) |

| Attack Complexity | Low (AC:L) |

| Privileges Required | None (PR:N) |

| User Interaction | Required (UI:R) |

| Scope | Unchanged (S:U) |

| Confidentiality Impact | High (C:H) |

| Integrity Impact | High (I:H) |

| Availability Impact | High (A:H) |

| Vector String (3.1) | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |

| Vector String (4.0) | CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |


The 7.8–8.4 severity rating reflects the potential for complete system compromise with minimal attack complexity. The "Low" attack complexity indicates that no special conditions or tools are needed to craft a working exploit. The requirement for user interaction is the primary barrier, but social engineering and supply chain compromises can easily overcome this limitation in industrial settings where file sharing is common.


## Affected Products


AzeoTech DAQFactory:

  • Versions 21.1 and earlier are affected
  • No mention of patched versions in the advisory; users should check with AzeoTech for availability of version 21.2 or later

  • ## Mitigations


    Until a patched version is available, organizations should implement the following defensive measures:


    Immediate Actions:

  • Avoid opening .ctl files from unknown or untrusted sources
  • Implement strict access controls for documents, restricting .ctl file storage to folders writable only by administrative users
  • Enable "Safe Mode" when loading DAQFactory documents that have been outside organizational control, which provides limited execution capabilities

  • Operational Security:

  • Apply document editing passwords to sensitive DAQFactory documents to prevent unauthorized modification
  • Segment industrial control networks from business networks using firewalls
  • Ensure DAQFactory systems are not directly accessible from the internet
  • Use VPNs for remote access, keeping them updated to the latest version

  • Broader Recommendations:

  • Perform a risk assessment to identify which DAQFactory instances are most critical and prioritize protections for those systems
  • Monitor for any security updates from AzeoTech regarding version 22.0 or later
  • Educate users about social engineering attacks that may be used to deliver malicious .ctl files
  • Establish an incident reporting procedure for suspected exploitation attempts

  • ## References


  • CISA Vulnerability Alert: https://www.cisa.gov/advisories/
  • AzeoTech Official Website: https://www.azeotech.com/
  • CWE-843 Type Confusion: https://cwe.mitre.org/data/definitions/843.html
  • CISA ICS Recommended Practices: https://www.cisa.gov/ics/

  • ---


    ## HackWire Analysis


    This vulnerability highlights a persistent weakness in industrial software security: the underestimation of social engineering as an attack vector. While enterprise software has largely moved away from simple user-interaction exploits, control system vendors often lag behind, treating these attack paths as lower-priority. The fact that CVE-2026-12390 requires only opening a file—the default user action in any industrial environment—makes it a near-perfect pivot point for supply chain attacks.


    Consider the attack scenario: A threat actor compromises an engineering vendor's file repository or intercepts a software update notification email. They replace a legitimate .ctl configuration file with a malicious one, and it propagates to dozens of manufacturing facilities. Unlike a networked attack that triggers IDS/IPS alerts, this flies through email gateways undetected and lands in the hands of operators who rightfully expect to receive .ctl files from their vendors.


    The CISA advisory's recommendation to run DAQFactory in "Safe Mode" is important but likely underutilized—many operators run DAQFactory with full privileges out of convenience, and asking them to change workflows during production operations is a hard sell. Organizations should audit which DAQFactory instances are actually running with administrative privileges and implement privilege separation immediately.


    Notably, there is no evidence of public exploitation yet, but that window closes quickly once patches are released. The 7-10 day gap between patch availability and widespread deployment in industrial environments is typically when targeted attacks occur. Organizations should prioritize testing and deploying patches for DAQFactory as soon as they become available.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)