PatchSiren cyber security CVE debrief
CVE-2025-53416 Delta Electronics CVE debrief
CVE-2025-53416 affects Delta Electronics DTN Soft versions 2.1.0 and earlier. CISA states that a specially crafted project file can trigger deserialization of untrusted data and may allow arbitrary code execution; the supplied CVSS v3.1 vector is AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, which maps to a High severity score of 7.8. No KEV listing is included in the supplied data.
- Vendor
- Delta Electronics
- Product
- DTN Soft
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-07-29
- Original CVE updated
- 2025-07-29
- Advisory published
- 2025-07-29
- Advisory updated
- 2025-07-29
Who should care
OT/ICS administrators, control engineers, and security teams responsible for Delta Electronics DTN Soft installations, especially systems that routinely open or exchange project files.
Technical summary
The CISA CSAF advisory for ICSA-25-210-03 identifies a deserialization of untrusted data vulnerability in Delta Electronics DTN Soft. The affected product scope in the supplied advisory is Delta Electronics DTN Soft: <=2.1.0. The described attack path uses a specially crafted project file, and successful exploitation could lead to arbitrary code execution. The supplied CVSS v3.1 vector indicates local access and user interaction are required.
Defensive priority
High — prioritize patching affected DTN Soft installations and any related engineering workstations that process project files.
Recommended defensive actions
- Update Delta Electronics DTN Soft to version 2.1.0 or later using Delta Electronics' Download Center.
- If Delta Electronics DTM Soft is also installed, update it to version 1.6.0.0 or later.
- Treat project files from untrusted or unknown sources as unsafe until affected systems are patched.
- Review Delta Electronics advisory Delta-PCSA-2025-00009 and follow CISA ICS recommended practices for industrial control systems.
Evidence notes
Primary evidence comes from the CISA CSAF advisory ICSA-25-210-03 (published 2025-07-29) and its remediation guidance. The advisory text states that Delta Electronics DTN Soft is affected by deserialization of untrusted data, that a specially crafted project file may enable arbitrary code execution, and that affected versions are <=2.1.0. The remediation section states DTN Soft should be updated to v2.1.0 or later; if DTM Soft is installed, it should be updated to v1.6.0.0 or later.
Official resources
-
CVE-2025-53416 CVE record
CVE.org
-
CVE-2025-53416 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
CISA published ICSA-25-210-03 for CVE-2025-53416 on 2025-07-29, and the supplied data uses that date as the CVE publication context. The supplied enrichment does not identify this vulnerability as a CISA KEV item.