VYPR
Vendor

Delta Electronics

Products
34
CVEs
276
Across products
294
Status
Private

Products

34
View all 34 products →

Recent CVEs

276
View all 276 CVEs →
  • CVE-2018-10594CriJun 26, 2018
    risk 0.72cvss 9.8epss 0.69

    Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPSimulator EH2, EH3, ES2, SE, SS2 and AHSIM_5x0, AHSIM_5x1) utilize a fixed-length stack buffer where an unverified length value can be read from the network…

  • CVE-2023-1133CriMar 27, 2023
    risk 0.71cvss 9.8epss 0.50

    Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service accepts the unverified UDP packets and deserializes the content, which could allow an unauthenticated…

  • CVE-2024-4548CriMay 6, 2024
    risk 0.69cvss 9.8epss 0.29

    An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth…

  • CVE-2021-38406HigKEVSep 17, 2021
    risk 0.69cvss 7.8epss 0.78

    Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in multiple out-of-bounds write instances. An attacker could leverage this vulnerability to execute code in the context of…

  • CVE-2021-32955CriAug 30, 2021
    risk 0.67cvss 9.8epss 0.37

    Delta Electronics DIAEnergie Version 1.7.5 and prior allows unrestricted file uploads, which may allow an attacker to remotely execute code.

  • CVE-2022-41772CriOct 31, 2022
    risk 0.66cvss 9.8epss 0.25

    Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters used in path traversal. This path traversal could result in remote code execution.

  • CVE-2025-58321CriSep 11, 2025
    risk 0.65cvss 10.0epss 0.01

    Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.

  • CVE-2024-10456CriOct 30, 2024
    risk 0.65cvss 9.8epss 0.18

    Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserialization vulnerability that targets the Device-Gateway, which could allow deserialization of arbitrary .NET objects prior to authentication.

  • CVE-2023-47207CriNov 30, 2023
    risk 0.65cvss 9.8epss 0.17

    In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute code with local administrator privileges.

  • CVE-2022-41657CriOct 31, 2022
    risk 0.65cvss 9.8epss 0.21

    Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized into memory to be used in file operation application programmable interfaces (APIs). This could create arbitrary files, which could be used in API operations…

  • CVE-2022-38142CriOct 31, 2022
    risk 0.65cvss 9.8epss 0.18

    Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-Gateway service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon…

  • CVE-2022-43775CriOct 26, 2022
    risk 0.65cvss 9.8epss 0.21

    The HICT_Loop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system.

  • CVE-2022-1378CriMay 2, 2022
    risk 0.65cvss 9.8epss 0.19

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_pgHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-1367CriMay 2, 2022
    risk 0.65cvss 9.8epss 0.19

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in Handler_TCV.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-1366CriMay 2, 2022
    risk 0.65cvss 9.8epss 0.19

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerChart.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-25347CriMar 29, 2022
    risk 0.65cvss 9.8epss 0.11

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to path traversal attacks, which may allow an attacker to write arbitrary files to locations on the file system.

  • CVE-2021-38393CriAug 30, 2021
    risk 0.65cvss 9.8epss 0.20

    A Blind SQL injection vulnerability exists in the /DataHandler/HandlerAlarmGroup.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter agid before using it as…

  • CVE-2021-38390CriAug 30, 2021
    risk 0.65cvss 9.8epss 0.20

    A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter egyid before using it as…

  • CVE-2026-12819CriJun 30, 2026
    risk 0.64cvss epss 0.00

    Delta Electronics DVP12SE PLC exposes a Modbus TCP service over a specified port without authentication or access control, permitting unauthenticated interaction with security-sensitive PLC functions.

  • CVE-2026-12818CriJun 30, 2026
    risk 0.64cvss epss 0.00

    Delta Electronics DVP12SE PLCs are susceptible to a resource allocation vulnerability without limits or throttling (CWE-770) within their Modbus TCP service.