PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-1949 Deltaww CVE debrief

CVE-2026-1949 is a critical vulnerability in Delta Electronics AS320T firmware affecting the web service GET/PUT request handler. The issue is an incorrect calculation of stack buffer size, which can have high impact because the published CVSS vector rates the flaw as network-reachable, unauthenticated, and capable of affecting confidentiality, integrity, and availability. NVD lists firmware versions before 1.16 as vulnerable, and Delta’s advisory covers this issue alongside related AS320T vulnerabilities.

Vendor
Deltaww
Product
Unknown
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-24
Original CVE updated
2026-05-11
Advisory published
2026-04-24
Advisory updated
2026-05-11

Who should care

OT/ICS defenders, plant operators, and system integrators who manage Delta Electronics AS320T devices, especially any unit running firmware earlier than 1.16.

Technical summary

The flaw is a stack buffer sizing error in the AS320T web service GET/PUT request handler. NVD maps the weakness to CWE-131 and rates the issue CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating a remotely reachable issue with no privileges or user interaction required. The NVD CPE data marks AS320T firmware versions before 1.16 as affected.

Defensive priority

Immediate. Treat as a critical exposure on any internet- or network-reachable AS320T management interface and prioritize firmware remediation ahead of routine maintenance.

Recommended defensive actions

  • Identify all Delta Electronics AS320T devices in the environment and confirm their firmware version.
  • Prioritize devices running firmware earlier than 1.16 for immediate remediation.
  • Apply the vendor-recommended firmware update or move to a non-vulnerable version at or above 1.16.
  • Restrict access to the web service management interface to trusted admin networks only until remediation is complete.
  • Monitor vendor advisory materials for any additional guidance related to the AS320T vulnerability set.

Evidence notes

Primary evidence comes from the NVD record for CVE-2026-1949 and the linked Delta Electronics advisory. The NVD entry shows publication on 2026-04-24 and modification on 2026-05-11, lists CWE-131, and marks AS320T firmware versions before 1.16 as vulnerable. The vendor advisory referenced by NVD is titled for multiple AS320T vulnerabilities including CVE-2026-1949.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-1949 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-1949

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-1949 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-1949

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://filecenter.deltaww.com/news/download/doc/Delta-PCSA-2026-00006_AS320T%20Multiple%20vulnerabilities%20(CVE-2026-1949,%201950,%201951,%201952).pdf

    759f5e80-c8e1-4224-bead-956d7b33c98b - Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.