Delta Electronics DIAEnergie SQL Injection in HandlerExport.ashx/Calendar.ashx
Description
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerExport.ashx/Calendar. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A blind SQL injection in Delta Electronics DIAEnergie's HandlerExport.ashx/Calendar allows remote unauthenticated attackers to execute arbitrary SQL and system commands.
Vulnerability
Delta Electronics DIAEnergie, an industrial energy management system, is vulnerable to a blind SQL injection in the HandlerExport.ashx/Calendar endpoint. All versions prior to 1.8.02.004 (as per the CVE description) or prior to 1.9 (according to the CISA advisory [1]) are affected. The vulnerability allows an attacker to inject arbitrary SQL queries without prior authentication.
Exploitation
An unauthenticated attacker with network access can exploit this vulnerability by sending crafted HTTP requests to the vulnerable endpoint. The attack requires low complexity and no user interaction. By manipulating input parameters, the attacker can perform SQL injection, potentially enumerating database contents or modifying data.
Impact
Successful exploitation enables the attacker to retrieve and modify sensitive database contents, as well as execute system commands on the underlying system. This can lead to full compromise of the DIAEnergie application and the associated industrial control system, impacting confidentiality, integrity, and availability.
Mitigation
Delta Electronics has addressed this vulnerability in version 1.9 of DIAEnergie, as indicated in the CISA advisory [1]. Users are strongly advised to update to this or a later version. If upgrading is not immediately possible, apply network segmentation and restrict access to the affected endpoint as a workaround.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<1.8.02.004+ 1 more
- (no CPE)range: <1.8.02.004
- (no CPE)range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.cisa.gov/uscert/ics/advisories/icsa-22-081-01mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.