VYPR
Unrated severityNVD Advisory· Published Mar 29, 2022· Updated Apr 16, 2025

Delta Electronics DIAEnergie SQL Injection in HandlerPage_KID.ashx

CVE-2022-26069

Description

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerPage_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Delta Electronics DIAEnergie versions prior to 1.8.02.004 contain a blind SQL injection vulnerability in HandlerPage_KID.ashx, allowing remote attackers to execute arbitrary SQL and system commands.

Vulnerability

Delta Electronics DIAEnergie, an industrial energy management system, is vulnerable to a blind SQL injection in the HandlerPage_KID.ashx component. This affects all versions prior to 1.8.02.004. The flaw is a classic improper neutralization of special elements used in an SQL command (CWE-89), enabling an unauthenticated attacker to inject arbitrary SQL queries [1].

Exploitation

An attacker can exploit this vulnerability remotely over the network without needing authentication or user interaction. The attack complexity is low. By sending specially crafted HTTP requests to the vulnerable endpoint, the attacker can perform blind SQL injection to extract data, modify database contents, and ultimately execute operating system commands [1].

Impact

Successful exploitation allows the attacker to retrieve and modify all database contents, including sensitive information. More critically, the SQL injection can be leveraged to execute arbitrary system commands on the underlying server, leading to full compromise of confidentiality, integrity, and availability. The CVSS v3 score is 9.8 (Critical) [1].

Mitigation

Delta Electronics released version 1.8.02.004 to address this vulnerability. Users are urged to update to version 1.9 or later as recommended in the CISA advisory. If immediate patching is not possible, network segmentation and restricting access to DIAEnergie web interfaces are advised. No workaround is available, and the vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.