VYPR

Vendor CVEs

Delta Electronics

All CVEs

276 total · sorted by risk
  • CVE-2023-43820HigJan 18, 2024
    risk 0.57cvss 8.8epss 0.01

    A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesPrevValueLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to…

  • CVE-2023-43819HigJan 18, 2024
    risk 0.57cvss 8.8epss 0.01

    A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the InitialMacroLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to…

  • CVE-2023-43818HigJan 18, 2024
    risk 0.57cvss 8.8epss 0.01

    A buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

  • CVE-2023-46690HigNov 30, 2023
    risk 0.57cvss 8.8epss 0.02

    In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an attacker to write to any file to any location of the filesystem, which could lead to remote code execution.

  • CVE-2023-30765HigJul 10, 2023
    risk 0.57cvss 8.8epss 0.02

    ​Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contain improper access controls that could allow an attacker to alter privilege management configurations, resulting in privilege escalation.

  • CVE-2023-1144HigMar 27, 2023
    risk 0.57cvss 8.8epss 0.01

    Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contains an improper access control vulnerability in which an attacker can use the Device-Gateway service and bypass authorization, which could result in privilege escalation.

  • CVE-2023-1143HigMar 27, 2023
    risk 0.57cvss 8.8epss 0.01

    In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use Lua scripts, which could allow an attacker to remotely execute arbitrary code.

  • CVE-2023-1141HigMar 27, 2023
    risk 0.57cvss 8.8epss 0.02

    Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a command injection vulnerability that could allow an attacker to inject arbitrary commands, which could result in remote code execution.

  • CVE-2023-1139HigMar 27, 2023
    risk 0.57cvss 8.8epss 0.01

    Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-gateway service, which could allow deserialization of requests prior to authentication, resulting in remote code execution.

  • CVE-2023-0822HigFeb 17, 2023
    risk 0.57cvss 8.8epss 0.01

    The affected product DIAEnergie (versions prior to v1.9.03.001) contains improper authorization, which could allow an unauthorized user to bypass authorization and access privileged functionality.

  • CVE-2023-0444HigJan 26, 2023
    risk 0.57cvss 8.8epss 0.01

    A privilege escalation vulnerability exists in Delta Electronics InfraSuite Device Master 00.00.02a. A default user 'User', which is in the 'Read Only User' group, can view the password of another default user 'Administrator', which is in the 'Administrator' group. This allows…

  • CVE-2022-43506HigNov 17, 2022
    risk 0.57cvss 8.8epss 0.01

    SQL Injection in HandlerTag_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network

  • CVE-2022-43457HigNov 17, 2022
    risk 0.57cvss 8.8epss 0.01

    SQL Injection in HandlerPage_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network

  • CVE-2022-43447HigNov 17, 2022
    risk 0.57cvss 8.8epss 0.01

    SQL Injection in AM_EBillAnalysis.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network

  • CVE-2022-41775HigNov 17, 2022
    risk 0.57cvss 8.8epss 0.01

    SQL Injection in Handler_CFG.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network

  • CVE-2022-41779HigOct 31, 2022
    risk 0.57cvss 8.8epss 0.01

    Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize network packets without proper verification. If the device connects to an attacker-controlled server, the attacker could send maliciously crafted packets that would be deserialized and executed,…

  • CVE-2022-41644HigOct 31, 2022
    risk 0.57cvss 8.8epss 0.01

    Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lacks authentication for a function that changes group privileges. An attacker could use this to create a denial-of-service state or escalate their own privileges.

  • CVE-2022-41702HigOct 27, 2022
    risk 0.57cvss 8.7epss 0.11

    The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the InsertReg API.

  • CVE-2022-41701HigOct 27, 2022
    risk 0.57cvss 8.7epss 0.11

    The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutShift API.

  • CVE-2022-41651HigOct 27, 2022
    risk 0.57cvss 8.7epss 0.11

    The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the SetPF API.

  • CVE-2022-41555HigOct 27, 2022
    risk 0.57cvss 8.7epss 0.11

    The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutLineMessageSetting API.

  • CVE-2022-40965HigOct 27, 2022
    risk 0.57cvss 8.7epss 0.11

    The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PostEnergyType API.

  • CVE-2021-38418HigNov 3, 2021
    risk 0.57cvss 8.8epss 0.01

    Delta Electronics DIALink versions 1.2.4.0 and prior runs by default on HTTP, which may allow an attacker to be positioned between the traffic and perform a machine-in-the-middle attack to access information without authorization.

  • CVE-2018-7509HigMay 4, 2018
    risk 0.57cvss 8.8epss 0.03

    WPLSoft in Delta Electronics versions 2.45.0 and prior writes data from a file outside the bounds of the intended buffer space, which could cause memory corruption or may allow remote code execution.

  • CVE-2018-7507HigMay 4, 2018
    risk 0.57cvss 8.8epss 0.03

    WPLSoft in Delta Electronics versions 2.45.0 and prior utilizes a fixed length heap buffer where a value larger than the buffer can be read from a file into the buffer, causing the buffer to be overwritten, which may allow remote code execution or cause the application to crash.

  • CVE-2018-7494HigMay 4, 2018
    risk 0.57cvss 8.8epss 0.03

    WPLSoft in Delta Electronics versions 2.45.0 and prior utilizes a fixed length stack buffer where a value larger than the buffer can be read from a file into the buffer, causing the buffer to be overwritten, which may allow remote code execution or cause the application to crash.

  • CVE-2025-53418HigAug 26, 2025
    risk 0.56cvss 8.6epss 0.00

    Delta Electronics COMMGR has Stack-based Buffer Overflow vulnerability.

  • CVE-2026-12578HigJun 30, 2026
    risk 0.55cvss epss 0.00

    The affected product is vulnerable to a deserialization of untrusted data, which may allow an attacker to execute arbitrary code.

  • CVE-2024-28171HigMar 21, 2024
    risk 0.53cvss 8.1epss 0.01

    It is possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on the file system, then the original file will be overwritten.

  • CVE-2024-25567HigMar 21, 2024
    risk 0.53cvss 8.1epss 0.01

    Path traversal attack is possible and write outside of the intended directory and may access sensitive information. If a file name is specified that already exists on the file system, then the original file will be overwritten.

  • CVE-2023-5131HigJan 18, 2024
    risk 0.53cvss 8.2epss 0.01

    A heap buffer-overflow exists in Delta Electronics ISPSoft. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DVP file to achieve code execution.

  • CVE-2023-5130HigJan 18, 2024
    risk 0.53cvss 8.2epss 0.01

    A buffer overflow vulnerability exists in Delta Electronics WPLSoft. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DVP file to achieve code execution.

  • CVE-2026-3094HigMar 4, 2026
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

  • CVE-2026-0975HigJan 16, 2026
    risk 0.51cvss 7.8epss 0.01

    Delta Electronics DIAView has Command Injection vulnerability.

  • CVE-2025-59300HigOct 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

  • CVE-2025-59299HigOct 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

  • CVE-2025-59298HigOct 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

  • CVE-2025-59297HigOct 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

  • CVE-2025-58319HigSep 24, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

  • CVE-2025-58317HigSep 24, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

  • CVE-2025-53419HigAug 26, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics COMMGR has Code Injection vulnerability.

  • CVE-2025-53416HigJun 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DTN Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution

  • CVE-2025-53415HigJun 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DTM Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution

  • CVE-2025-4125HigApr 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that could allow an attacker to execute arbitrary code when parsing ISP file.

  • CVE-2025-4124HigApr 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that could allow an attacker to execute arbitrary code when parsing ISP file.

  • CVE-2025-22884HigApr 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-Based buffer overflow vulnerability that could allow an attacker to execute arbitrary code when parsing DVP file.

  • CVE-2025-22883HigApr 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that could allow an attacker to execute arbitrary code when parsing DVP file.

  • CVE-2025-22882HigApr 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-Based buffer overflow vulnerability that could allow an attacker to leverage debugging logic to execute arbitrary code when parsing CBDGL file.

  • CVE-2025-22881HigFeb 26, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the…

  • CVE-2025-22880HigFeb 7, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the…

Page 3 of 6