PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-1950 Deltaww CVE debrief

CVE-2026-1950 is a critical vulnerability in Delta Electronics AS320T firmware affecting versions before 1.16. The issue is described as missing length checking on a buffer that handles file names, and NVD maps it to CWE-121 (stack-based buffer overflow). NVD rates the flaw 9.8/CRITICAL with a network attack vector and no privileges or user interaction required, so exposed or remotely reachable devices should be treated as urgent remediation candidates.

Vendor
Deltaww
Product
Unknown
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-24
Original CVE updated
2026-05-11
Advisory published
2026-04-24
Advisory updated
2026-05-11

Who should care

Organizations that operate Delta Electronics AS320T devices, especially if the firmware is older than 1.16 or the device is reachable over a network, should prioritize this issue. Security teams responsible for industrial or embedded device fleets should also check whether AS320T firmware is present in their inventory.

Technical summary

NVD lists the affected component as cpe:2.3:o:deltaww:as320t_firmware with vulnerable versions ending before 1.16. The weakness is identified as CWE-121, and the CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The source description says there is no length check for the buffer associated with the file name, which is consistent with a stack-based buffer overflow condition.

Defensive priority

Immediate

Recommended defensive actions

  • Inventory all Delta Electronics AS320T devices and confirm installed firmware versions.
  • Upgrade AS320T firmware to version 1.16 or later, following the vendor advisory and maintenance guidance.
  • Restrict network access to management or service interfaces until affected systems are patched.
  • Validate remediation using the vendor advisory and NVD record for CVE-2026-1950.
  • Monitor affected systems for unexpected crashes, reboots, or other instability while remediation is underway.

Evidence notes

This debrief is based on the NVD CVE record and the linked Delta Electronics advisory referenced by NVD. NVD marks the issue as analyzed, gives it CVSS 9.8 with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, and lists CWE-121. The vulnerable CPE range is firmware before 1.16. The NVD reference list includes the vendor advisory for multiple AS320T vulnerabilities covering CVE-2026-1949 through CVE-2026-1952.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-1950 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-1950

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-1950 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-1950

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://filecenter.deltaww.com/news/download/doc/Delta-PCSA-2026-00006_AS320T%20Multiple%20vulnerabilities%20(CVE-2026-1949,%201950,%201951,%201952).pdf

    759f5e80-c8e1-4224-bead-956d7b33c98b - Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.