Delta Electronics DIAEnergie SQL Injection in DIAE_hierarchyHandler.ashx
Description
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerTag_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A blind SQL injection in Delta Electronics DIAEnergie's HandlerTag_KID.ashx allows remote attackers to execute arbitrary SQL and system commands.
Vulnerability
A blind SQL injection vulnerability exists in the HandlerTag_KID.ashx endpoint of Delta Electronics DIAEnergie. All versions prior to 1.8.02.004 (and subsequently prior to 1.9 per updated advisory) are affected. The vulnerability is remotely exploitable without authentication, requiring only a crafted HTTP request to the vulnerable handler.
Exploitation
An attacker can send specially crafted HTTP requests to HandlerTag_KID.ashx to inject arbitrary SQL queries. The blind nature of the injection means the attacker may need to use time-based or error-based techniques to extract information. No prior authentication or user interaction is required, and the attack complexity is low.
Impact
Successful exploitation allows the attacker to retrieve and modify database contents, and execute system commands on the underlying system. This leads to full compromise of confidentiality, integrity, and availability, potentially enabling remote code execution and complete control of the affected device.
Mitigation
Delta Electronics released version 1.9 to address this vulnerability. Users should update to 1.9 or later. No workarounds are documented. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog as of the advisory publication date [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<1.8.02.004+ 1 more
- (no CPE)range: <1.8.02.004
- (no CPE)range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.cisa.gov/uscert/ics/advisories/icsa-22-081-01mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.