PatchSiren cyber security CVE debrief
CVE-2026-1949 Deltaww CVE debrief
CVE-2026-1949 is a critical vulnerability in Delta Electronics AS320T firmware affecting the web service GET/PUT request handler. The issue is an incorrect calculation of stack buffer size, which can have high impact because the published CVSS vector rates the flaw as network-reachable, unauthenticated, and capable of affecting confidentiality, integrity, and availability. NVD lists firmware versions before 1.16 as vulnerable, and Delta’s advisory covers this issue alongside related AS320T vulnerabilities.
- Vendor
- Deltaww
- Product
- Unknown
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-24
- Original CVE updated
- 2026-05-11
- Advisory published
- 2026-04-24
- Advisory updated
- 2026-05-11
Who should care
OT/ICS defenders, plant operators, and system integrators who manage Delta Electronics AS320T devices, especially any unit running firmware earlier than 1.16.
Technical summary
The flaw is a stack buffer sizing error in the AS320T web service GET/PUT request handler. NVD maps the weakness to CWE-131 and rates the issue CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating a remotely reachable issue with no privileges or user interaction required. The NVD CPE data marks AS320T firmware versions before 1.16 as affected.
Defensive priority
Immediate. Treat as a critical exposure on any internet- or network-reachable AS320T management interface and prioritize firmware remediation ahead of routine maintenance.
Recommended defensive actions
- Identify all Delta Electronics AS320T devices in the environment and confirm their firmware version.
- Prioritize devices running firmware earlier than 1.16 for immediate remediation.
- Apply the vendor-recommended firmware update or move to a non-vulnerable version at or above 1.16.
- Restrict access to the web service management interface to trusted admin networks only until remediation is complete.
- Monitor vendor advisory materials for any additional guidance related to the AS320T vulnerability set.
Evidence notes
Primary evidence comes from the NVD record for CVE-2026-1949 and the linked Delta Electronics advisory. The NVD entry shows publication on 2026-04-24 and modification on 2026-05-11, lists CWE-131, and marks AS320T firmware versions before 1.16 as vulnerable. The vendor advisory referenced by NVD is titled for multiple AS320T vulnerabilities including CVE-2026-1949.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-1949 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-1949
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-1949 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-1949
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://filecenter.deltaww.com/news/download/doc/Delta-PCSA-2026-00006_AS320T%20Multiple%20vulnerabilities%20(CVE-2026-1949,%201950,%201951,%201952).pdf
759f5e80-c8e1-4224-bead-956d7b33c98b - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.