PatchSiren

deltaww CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH deltaww CVE published 2026-08-24

CVE-2026-78317

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-78317 was published on 2026-08-24T10:16:40.810Z and has not been modified since then. This CVE record indicates a SQL Injection vulnerability in Delta DIAEnergie v1.11.00.002, which could allow remote code execution. The vulnerability has a CVSS score of 8.8 and is classified as HIGH severity. Organizations sho [truncated]

HIGH deltaww CVE published 2026-08-24

CVE-2026-78316

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-24T10:16:40.667Z and has not been modified since then. The vulnerability is a SQL Injection in Delta DIAEnergie v1.11.00.002, which could allow remote code execution. The CVE record indicates a CVSS score of 8.8 and is classified as HIGH severity. However, details are limited, and further verificati [truncated]

HIGH deltaww CVE published 2026-08-24

CVE-2026-78315

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-24T10:16:40.510Z and has not been modified since then. The vulnerability is a SQL Injection in Delta DIAEnergie v1.11.00.002, which could allow remote code execution. The CVE record indicates a CVSS score of 8.8 and is classified as HIGH severity. However, details are limited, and further verificati [truncated]

CRITICAL Deltaww CVE published 2026-04-24

CVE-2026-1952

CVE-2026-1952 is a critical-severity vulnerability affecting Delta Electronics AS320T firmware. NVD describes it as a denial-of-service issue tied to an undocumented subfunction, with a network attack vector and no privileges or user interaction required. The NVD record also lists vulnerable AS320T firmware versions prior to 1.16. For industrial or OT environments, this is most important where the device [truncated]

CRITICAL Deltaww CVE published 2026-04-24

CVE-2026-1951

CVE-2026-1951 is a critical Delta Electronics AS320T firmware flaw tied to missing length checks for a directory-name buffer. NVD assigns it CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating a remotely reachable issue with no privileges or user interaction required. NVD’s affected CPE range marks AS320T firmware versions earlier than 1.12 as vulnerable. The vendor advisory linked in NVD cover [truncated]

CRITICAL Deltaww CVE published 2026-04-24

CVE-2026-1950

CVE-2026-1950 is a critical vulnerability in Delta Electronics AS320T firmware affecting versions before 1.16. The issue is described as missing length checking on a buffer that handles file names, and NVD maps it to CWE-121 (stack-based buffer overflow). NVD rates the flaw 9.8/CRITICAL with a network attack vector and no privileges or user interaction required, so exposed or remotely reachable devices sh [truncated]

CRITICAL Deltaww CVE published 2026-04-24

CVE-2026-1949

CVE-2026-1949 is a critical vulnerability in Delta Electronics AS320T firmware affecting the web service GET/PUT request handler. The issue is an incorrect calculation of stack buffer size, which can have high impact because the published CVSS vector rates the flaw as network-reachable, unauthenticated, and capable of affecting confidentiality, integrity, and availability. NVD lists firmware versions befo [truncated]

HIGH DeltaWW CVE published 2026-04-16

CVE-2026-5726

CVE-2026-5726 is a high-severity stack-based buffer overflow in Delta Electronics ASDA-Soft identified in CISA’s advisory ICSA-26-106-01. According to the advisory, the issue affects ASDA-Soft version 7.2.0.0 during parsing of malformed .par files, and Delta recommends upgrading to v7.2.6.0 or later. The supplied CVSS vector indicates a local attack with required user interaction and high impact to confid [truncated]