Delta Electronics Delta Industrial Automation DOPSoft DPS File InitialMacroLen Buffer Overflow Remote Code Execution
Description
A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the InitialMacroLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stack buffer overflow in Delta Electronics DOPSoft DPS file parsing allows remote code execution via crafted file.
Vulnerability
A stack-based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the InitialMacroLen field of a DPS file. The affected product is end-of-life and no specific version range is provided; all versions are presumed vulnerable. The vulnerability is triggered during the processing of a specially crafted DPS file [1].
Exploitation
An unauthenticated remote attacker can exploit this vulnerability by convincing a user to open a malicious DPS file. No additional privileges or network access beyond delivering the file are required. The attacker crafts a DPS file with an oversized InitialMacroLen value, which when parsed by DOPSoft causes a stack buffer overflow [1].
Impact
Successful exploitation results in remote code execution in the context of the DOPSoft application. The attacker can achieve arbitrary code execution, potentially leading to full compromise of the affected system [1].
Mitigation
The product is end-of-life and no patches are available. Users are advised to discontinue use of DOPSoft and migrate to a supported alternative. No workarounds are provided in the available references [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: 2.00.00.00
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.