Azeotech · Daqfactory · CVE-2026-12390
**Name of the Vulnerable Software and Affected Versions**
AzeoTech DAQFactory versions prior to 21.2
**Description**
A Type Confusion issue exists where an attacker can use specially crafted `.ctl` files to achieve arbitrary code execution. Type Confusion occurs when a program accesses a resource using a type that is different from the type it was originally allocated with, leading to unexpected behavior.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Password-protect `.ctl` documents as a mitigation measure.