PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-53416 Delta Electronics CVE debrief

CVE-2025-53416 affects Delta Electronics DTN Soft versions 2.1.0 and earlier. CISA states that a specially crafted project file can trigger deserialization of untrusted data and may allow arbitrary code execution; the supplied CVSS v3.1 vector is AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, which maps to a High severity score of 7.8. No KEV listing is included in the supplied data.

Vendor
Delta Electronics
Product
DTN Soft
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2025-07-29
Original CVE updated
2025-07-29
Advisory published
2025-07-29
Advisory updated
2025-07-29

Who should care

OT/ICS administrators, control engineers, and security teams responsible for Delta Electronics DTN Soft installations, especially systems that routinely open or exchange project files.

Technical summary

The CISA CSAF advisory for ICSA-25-210-03 identifies a deserialization of untrusted data vulnerability in Delta Electronics DTN Soft. The affected product scope in the supplied advisory is Delta Electronics DTN Soft: <=2.1.0. The described attack path uses a specially crafted project file, and successful exploitation could lead to arbitrary code execution. The supplied CVSS v3.1 vector indicates local access and user interaction are required.

Defensive priority

High — prioritize patching affected DTN Soft installations and any related engineering workstations that process project files.

Recommended defensive actions

  • Update Delta Electronics DTN Soft to version 2.1.0 or later using Delta Electronics' Download Center.
  • If Delta Electronics DTM Soft is also installed, update it to version 1.6.0.0 or later.
  • Treat project files from untrusted or unknown sources as unsafe until affected systems are patched.
  • Review Delta Electronics advisory Delta-PCSA-2025-00009 and follow CISA ICS recommended practices for industrial control systems.

Evidence notes

Primary evidence comes from the CISA CSAF advisory ICSA-25-210-03 (published 2025-07-29) and its remediation guidance. The advisory text states that Delta Electronics DTN Soft is affected by deserialization of untrusted data, that a specially crafted project file may enable arbitrary code execution, and that affected versions are <=2.1.0. The remediation section states DTN Soft should be updated to v2.1.0 or later; if DTM Soft is installed, it should be updated to v1.6.0.0 or later.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-53416 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-53416

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-53416 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-53416

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-210-03.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-210-03

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.