# Type Confusion Flaw in AzeoTech DAQFactory Allows Arbitrary Code Execution on Industrial Systems
## The Threat
A critical type confusion vulnerability in AzeoTech DAQFactory threatens industrial control systems worldwide, allowing attackers to execute arbitrary code through specially crafted .ctl files. CVE-2026-12390 exploits a flaw in how the software handles data type validation, enabling an attacker to bypass security boundaries and gain full system control once a malicious file is opened.
The vulnerability is particularly dangerous because it requires minimal preconditions to exploit. An attacker simply needs to deliver a malicious .ctl (control) file to a target user—via email, compromised website, or supply chain vector. When the user opens the file, the type confusion flaw allows the attacker's code to execute with the same privileges as the user running DAQFactory. For systems running DAQFactory with administrative rights (common in industrial deployments), this translates to complete system compromise.
AzeoTech DAQFactory is widely deployed across critical manufacturing environments globally. The software is used for data acquisition, process monitoring, and automation in plants that manage everything from chemical production to pharmaceutical manufacturing. A vulnerability in this class of software could disrupt production lines, compromise safety systems, or expose sensitive operational data. The fact that the attack requires only user interaction—not network connectivity—makes it ideal for targeted attacks against specific industrial organizations.
## Severity and Impact
| Aspect | Details |
|--------|---------|
| CVE Identifier | CVE-2026-12390 |
| Vulnerability Type | Type Confusion (CWE-843: Access of Resource Using Incompatible Type) |
| CVSS 3.1 Score | 7.8 (HIGH) |
| CVSS 4.0 Score | 8.4 (HIGH) |
| Attack Vector | Local (AV:L) |
| Attack Complexity | Low (AC:L) |
| Privileges Required | None (PR:N) |
| User Interaction | Required (UI:R) |
| Scope | Unchanged (S:U) |
| Confidentiality Impact | High (C:H) |
| Integrity Impact | High (I:H) |
| Availability Impact | High (A:H) |
| Vector String (3.1) | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| Vector String (4.0) | CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
The 7.8–8.4 severity rating reflects the potential for complete system compromise with minimal attack complexity. The "Low" attack complexity indicates that no special conditions or tools are needed to craft a working exploit. The requirement for user interaction is the primary barrier, but social engineering and supply chain compromises can easily overcome this limitation in industrial settings where file sharing is common.
## Affected Products
AzeoTech DAQFactory:
## Mitigations
Until a patched version is available, organizations should implement the following defensive measures:
Immediate Actions:
Operational Security:
Broader Recommendations:
## References
---
## HackWire Analysis
This vulnerability highlights a persistent weakness in industrial software security: the underestimation of social engineering as an attack vector. While enterprise software has largely moved away from simple user-interaction exploits, control system vendors often lag behind, treating these attack paths as lower-priority. The fact that CVE-2026-12390 requires only opening a file—the default user action in any industrial environment—makes it a near-perfect pivot point for supply chain attacks.
Consider the attack scenario: A threat actor compromises an engineering vendor's file repository or intercepts a software update notification email. They replace a legitimate .ctl configuration file with a malicious one, and it propagates to dozens of manufacturing facilities. Unlike a networked attack that triggers IDS/IPS alerts, this flies through email gateways undetected and lands in the hands of operators who rightfully expect to receive .ctl files from their vendors.
The CISA advisory's recommendation to run DAQFactory in "Safe Mode" is important but likely underutilized—many operators run DAQFactory with full privileges out of convenience, and asking them to change workflows during production operations is a hard sell. Organizations should audit which DAQFactory instances are actually running with administrative privileges and implement privilege separation immediately.
Notably, there is no evidence of public exploitation yet, but that window closes quickly once patches are released. The 7-10 day gap between patch availability and widespread deployment in industrial environments is typically when targeted attacks occur. Organizations should prioritize testing and deploying patches for DAQFactory as soon as they become available.
— HackWire Editorial
---
## Related Coverage