VYPR
Unrated severityNVD Advisory· Published Mar 29, 2022· Updated Apr 16, 2025

Delta Electronics DIAEnergie SQL Injection in HandlerCommon.ashx

CVE-2022-25980

Description

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerCommon.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A blind SQL injection vulnerability in Delta Electronics DIAEnergie allows remote, unauthenticated attackers to compromise database contents and execute system commands.

Vulnerability

A blind SQL injection vulnerability exists in the HandlerCommon.ashx endpoint of Delta Electronics DIAEnergie, affecting all versions prior to 1.8.02.004 (and subsequently all versions prior to 1.9 per later advisories [1]). The vulnerability is classified as CWE-89 and allows an attacker to inject arbitrary SQL queries without authentication [1].

Exploitation

An attacker can exploit this vulnerability remotely over the network with low complexity, requiring no authentication or user interaction [1]. The attacker sends crafted SQL queries to the vulnerable endpoint, leveraging blind SQL injection techniques to extract information or execute commands; the exact sequence of steps is not detailed in the available references, but the low attack complexity and remote exploitability are confirmed [1].

Impact

Successful exploitation allows the attacker to retrieve and modify database contents, and potentially execute arbitrary system commands at the privilege level of the application, leading to full compromise of confidentiality, integrity, and availability [1]. The CVSS v3 base score is 9.8, indicating critical severity [1].

Mitigation

Delta Electronics released DIAEnergie version 1.9 to address this vulnerability [1]. Users should update to version 1.9 or later. No workarounds are mentioned in the available references. The vulnerability is not known to be listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog as of the publication date.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.