VYPR
Unrated severityNVD Advisory· Published Mar 29, 2022· Updated Apr 16, 2025

Delta Electronics DIAEnergie SQL Injection in HandlerDialogECC.ashx

CVE-2022-26666

Description

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerECC.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A blind SQL injection vulnerability in Delta Electronics DIAEnergie's HandlerECC.ashx allows remote attackers to execute arbitrary SQL commands and system commands.

Vulnerability

A blind SQL injection vulnerability exists in the HandlerECC.ashx endpoint of Delta Electronics DIAEnergie. All versions prior to 1.9.0 (and prior to 1.8.02.004 per the CVE description) are affected. The vulnerability lies in improper neutralization of special elements used in SQL commands (CWE-89). An attacker can exploit this by sending malicious HTTP requests to the vulnerable endpoint. [1]

Exploitation

This vulnerability is remotely exploitable over the network with low attack complexity. No authentication or user interaction is required. An attacker can craft a POST request to HandlerECC.ashx with malicious SQL payloads in the input parameters, allowing them to inject arbitrary SQL queries. [1]

Impact

Successful exploitation allows an attacker to retrieve and modify database contents, execute arbitrary SQL queries, and execute system commands on the underlying operating system. This could lead to full compromise of the DIAEnergie system, including data exfiltration, data tampering, and potential remote code execution. [1]

Mitigation

Delta Electronics has released version 1.9.0 of DIAEnergie to address this vulnerability. Users should update to version 1.9.0 or later. The CISA advisory (ICSA-22-081-01) recommends upgrading immediately. No workarounds are available. [1]

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.