PatchSiren cyber security CVE debrief
CVE-2025-53416 Delta Electronics CVE debrief
CVE-2025-53416 affects Delta Electronics DTN Soft versions 2.1.0 and earlier. CISA states that a specially crafted project file can trigger deserialization of untrusted data and may allow arbitrary code execution; the supplied CVSS v3.1 vector is AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, which maps to a High severity score of 7.8. No KEV listing is included in the supplied data.
- Vendor
- Delta Electronics
- Product
- DTN Soft
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-07-29
- Original CVE updated
- 2025-07-29
- Advisory published
- 2025-07-29
- Advisory updated
- 2025-07-29
Who should care
OT/ICS administrators, control engineers, and security teams responsible for Delta Electronics DTN Soft installations, especially systems that routinely open or exchange project files.
Technical summary
The CISA CSAF advisory for ICSA-25-210-03 identifies a deserialization of untrusted data vulnerability in Delta Electronics DTN Soft. The affected product scope in the supplied advisory is Delta Electronics DTN Soft: <=2.1.0. The described attack path uses a specially crafted project file, and successful exploitation could lead to arbitrary code execution. The supplied CVSS v3.1 vector indicates local access and user interaction are required.
Defensive priority
High — prioritize patching affected DTN Soft installations and any related engineering workstations that process project files.
Recommended defensive actions
- Update Delta Electronics DTN Soft to version 2.1.0 or later using Delta Electronics' Download Center.
- If Delta Electronics DTM Soft is also installed, update it to version 1.6.0.0 or later.
- Treat project files from untrusted or unknown sources as unsafe until affected systems are patched.
- Review Delta Electronics advisory Delta-PCSA-2025-00009 and follow CISA ICS recommended practices for industrial control systems.
Evidence notes
Primary evidence comes from the CISA CSAF advisory ICSA-25-210-03 (published 2025-07-29) and its remediation guidance. The advisory text states that Delta Electronics DTN Soft is affected by deserialization of untrusted data, that a specially crafted project file may enable arbitrary code execution, and that affected versions are <=2.1.0. The remediation section states DTN Soft should be updated to v2.1.0 or later; if DTM Soft is installed, it should be updated to v1.6.0.0 or later.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-53416 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-53416
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-53416 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-53416
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-210-03.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-210-03
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.