VYPR
Unrated severityNVD Advisory· Published Mar 29, 2022· Updated Apr 16, 2025

Delta Electronics DIAEnergie SQL Injection in HandlerExport.ashx/Calendar.ashx

CVE-2022-26836

Description

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerExport.ashx/Calendar. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A blind SQL injection in Delta Electronics DIAEnergie's HandlerExport.ashx/Calendar allows remote unauthenticated attackers to execute arbitrary SQL and system commands.

Vulnerability

Delta Electronics DIAEnergie, an industrial energy management system, is vulnerable to a blind SQL injection in the HandlerExport.ashx/Calendar endpoint. All versions prior to 1.8.02.004 (as per the CVE description) or prior to 1.9 (according to the CISA advisory [1]) are affected. The vulnerability allows an attacker to inject arbitrary SQL queries without prior authentication.

Exploitation

An unauthenticated attacker with network access can exploit this vulnerability by sending crafted HTTP requests to the vulnerable endpoint. The attack requires low complexity and no user interaction. By manipulating input parameters, the attacker can perform SQL injection, potentially enumerating database contents or modifying data.

Impact

Successful exploitation enables the attacker to retrieve and modify sensitive database contents, as well as execute system commands on the underlying system. This can lead to full compromise of the DIAEnergie application and the associated industrial control system, impacting confidentiality, integrity, and availability.

Mitigation

Delta Electronics has addressed this vulnerability in version 1.9 of DIAEnergie, as indicated in the CISA advisory [1]. Users are strongly advised to update to this or a later version. If upgrading is not immediately possible, apply network segmentation and restrict access to the affected endpoint as a workaround.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.