VYPR
Unrated severityNVD Advisory· Published Oct 27, 2022· Updated Apr 16, 2025

Delta Electronics DIAEnergie

CVE-2022-41651

Description

The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the SetPF API.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

DIAEnergie prior to v1.9.01.002 contains stored XSS via the SetPF API, allowing arbitrary code injection after a victim loads the malicious input.

Vulnerability

DIAEnergie versions prior to v1.9.01.002 are vulnerable to stored cross-site scripting (XSS) via the SetPF API [1]. The application does not properly neutralize user input during web page generation (CWE-79), allowing an attacker to inject arbitrary script code that is stored and executed in the context of other users' browsers. Affected builds include all releases before v1.9.01.002.

Exploitation

An attacker needs low-privilege network access to the DIAEnergie web interface and must be able to craft HTTP requests to the SetPF API with malicious script payload [1]. No user interaction is required during the injection step, but the payload only executes when an authenticated victim navigates to a page that renders the stored input, resulting in a stored XSS attack with low complexity.

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session. This can lead to the theft of session cookies, modification of page content, or further attacks on the DIAEnergie system. The CVSS v3 score is 8.8, with a vector of (AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N) [1], indicating high confidentiality and integrity impact with no impact on availability.

Mitigation

Delta Electronics has released DIAEnergie version v1.9.01.002 to address this vulnerability. Users should update to this version or later [1]. CISA recommends reviewing the vendor advisory and applying the patch as soon as possible. No workaround is documented for the stored XSS via SetPF API specifically.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.