Delta Electronics, Inc. is a widely deployed vendor across industrial power-management, energy-infrastructure, and manufacturing-automation products, with a portfolio spanning multiple device classes and software platforms that present a substantial attack surface. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, with memory-safety and input-handling weakness classes including out-of-bounds writes and reads, stack-based buffer overflows, SQL injection, and cross-site scripting recurring across its DiaEnergie, InfraSuite Device Master, DOPsoft, and CNCsoft product lines. The elevation toward critical severity reflects the native-code and embedded-firmware characteristics of industrial control and energy-distribution software, where memory corruption and injection flaws can directly compromise system availability and physical operations. Defenders should prioritize asset inventory and network segmentation for these products and treat critical disclosures from this vendor as affecting potentially long-lived operational infrastructure; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Delta Electronics, Inc. over time
Of all the CVEs published by Delta Electronics, Inc. as a CNA, 78.3% affect products that Delta Electronics, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Delta Electronics, Inc., 15.8% are self-published by Delta Electronics, Inc. as a CNA.
Signals from CVEs in this vendor scope (297 CVEs).
297 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-38406HIGH Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in multiple out-of-bound | Sep 17, 2021 | 7.8 | 92 | YES | NO |
CVE-2018-10594CRITICAL Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPSimulator EH2, EH3, ES2, SE, SS2 and AHSIM_5x0, AHSIM_5x1) ut | Jun 26, 2018 | 9.8 | 83 | NO | YES |
CVE-2023-1133CRITICAL Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service acc | Mar 27, 2023 | 9.8 | 68 | NO | YES |
CVE-2024-4548CRITICAL An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the '~ | May 6, 2024 | 9.8 | 52 | NO | YES |
CVE-2021-32955CRITICAL Delta Electronics DIAEnergie Version 1.7.5 and prior allows unrestricted file uploads, which may allow an attacker to remotely execute code. | Aug 30, 2021 | 9.8 | 48 | NO | NO |
CVE-2022-41772CRITICAL
Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters used in path traversal. This path traversal could result in r | Oct 31, 2022 | 9.8 | 44 | NO | NO |
CVE-2022-41657CRITICAL
Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized into memory to be used in file operation application progra | Oct 31, 2022 | 9.8 | 41 | NO | NO |
CVE-2022-41133HIGH The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in GetDIAE_line_message_settingsListParameters. A low-privileged authen | Oct 27, 2022 | 8.8 | 41 | NO | NO |
CVE-2022-43775CRITICAL The HICT_Loop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system. | Oct 26, 2022 | 9.8 | 41 | NO | NO |
CVE-2022-1366CRITICAL Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerChart.ashx. This allows an attacker to inject arbitrary SQL | May 2, 2022 | 9.8 | 41 | NO | NO |
Signals from CVEs in this vendor scope (297 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Delta Electronics, Inc..
Media articles that mention a CVE ID that affects a product developed by Delta Electronics, Inc. — matched by CVE ID, not by vendor name.