Delta Electronics DIAEnergie
Description
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the SetPF API.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
DIAEnergie prior to v1.9.01.002 contains stored XSS via the SetPF API, allowing arbitrary code injection after a victim loads the malicious input.
Vulnerability
DIAEnergie versions prior to v1.9.01.002 are vulnerable to stored cross-site scripting (XSS) via the SetPF API [1]. The application does not properly neutralize user input during web page generation (CWE-79), allowing an attacker to inject arbitrary script code that is stored and executed in the context of other users' browsers. Affected builds include all releases before v1.9.01.002.
Exploitation
An attacker needs low-privilege network access to the DIAEnergie web interface and must be able to craft HTTP requests to the SetPF API with malicious script payload [1]. No user interaction is required during the injection step, but the payload only executes when an authenticated victim navigates to a page that renders the stored input, resulting in a stored XSS attack with low complexity.
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session. This can lead to the theft of session cookies, modification of page content, or further attacks on the DIAEnergie system. The CVSS v3 score is 8.8, with a vector of (AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N) [1], indicating high confidentiality and integrity impact with no impact on availability.
Mitigation
Delta Electronics has released DIAEnergie version v1.9.01.002 to address this vulnerability. Users should update to this version or later [1]. CISA recommends reviewing the vendor advisory and applying the patch as soon as possible. No workaround is documented for the stored XSS via SetPF API specifically.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: All
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.