Delta Electronics DIAEnergie SQL Injection in DIAE_eccoefficientHandler.ashx
Description
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in DIAE_eccoefficientHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Blind SQL injection in DIAE_eccoefficientHandler.ashx in Delta Electronics DIAEnergie allows remote unauthenticated attackers to execute arbitrary SQL and system commands.
Vulnerability
A blind SQL injection vulnerability exists in the DIAE_eccoefficientHandler.ashx endpoint of Delta Electronics DIAEnergie, an industrial energy management system. All versions prior to 1.8.02.004 are affected. The flaw occurs when user-supplied input is not properly sanitized before being used in SQL queries, allowing an attacker to inject arbitrary SQL statements.
Exploitation
An attacker can exploit this vulnerability remotely over the network without authentication and with low attack complexity. By sending a specially crafted HTTP request to the vulnerable handler, the attacker can inject SQL commands. Because the injection is blind, the attacker may need to infer query results through timing delays or boolean responses, but the attack does not require any user interaction or special privileges.
Impact
Successful exploitation enables the attacker to retrieve, modify, or delete database contents and execute arbitrary system commands on the underlying server. This can lead to full compromise of confidentiality, integrity, and availability of the affected system. The CVSS v3 base score is 9.8 (Critical).
Mitigation
Delta Electronics has addressed this vulnerability in version 1.8.02.004 and later releases. Users should update to the latest version as soon as possible. The CISA advisory [1] recommends upgrading to version 1.9 or higher. No workarounds are documented; applying the vendor patch is the only known mitigation.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2< 1.8.02.004+ 1 more
- (no CPE)range: < 1.8.02.004
- (no CPE)range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.cisa.gov/uscert/ics/advisories/icsa-22-081-01mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.