Delta Electronics Delta Industrial Automation DOPSoft DPS File wTextLen Buffer Overflow Remote Code Execution
Description
A buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A buffer overflow in Delta Electronics DOPSoft allows remote code execution when a user opens a crafted DPS file.
Vulnerability
A buffer overflow vulnerability exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing specially crafted DPS files. The flaw resides in the wTextLen field processing, where insufficient bounds checking allows an attacker to overwrite memory. The affected product is end-of-life (EOL) and the vulnerable version range includes all versions that process DPS files. No specific version numbers are provided in the available references [1].
Exploitation
Exploitation requires a remote, unauthenticated attacker to entice a user into opening a malicious DPS file [1]. No further authentication or network access is needed beyond the user action. The attacker crafts a DPS file with an oversized wTextLen value, which triggers a buffer overflow when DOPSoft reads the file. User interaction is required, typically achieved through social engineering or by hosting the file on a website [1].
Impact
Successful exploitation leads to remote code execution (RCE) in the context of the application [1]. The attacker can execute arbitrary commands, potentially gaining full control over the affected system, leading to compromise of confidentiality, integrity, and availability.
Mitigation
The affected product is end-of-life and no patches are available [1]. Users are advised to discontinue use of the software or isolate it from untrusted sources. No workaround is provided in the available references [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: 2.00.00.00
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.