Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Delta Electronics, Inc.

First CVE: Mar 15, 2018Active for: 8 yearsTotal CVEs: 297
68.2
VTI Score
TOP TARGET

Delta Electronics, Inc. is a widely deployed vendor across industrial power-management, energy-infrastructure, and manufacturing-automation products, with a portfolio spanning multiple device classes and software platforms that present a substantial attack surface. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, with memory-safety and input-handling weakness classes including out-of-bounds writes and reads, stack-based buffer overflows, SQL injection, and cross-site scripting recurring across its DiaEnergie, InfraSuite Device Master, DOPsoft, and CNCsoft product lines. The elevation toward critical severity reflects the native-code and embedded-firmware characteristics of industrial control and energy-distribution software, where memory corruption and injection flaws can directly compromise system availability and physical operations. Defenders should prioritize asset inventory and network segmentation for these products and treat critical disclosures from this vendor as affecting potentially long-lived operational infrastructure; live exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
297
Total CVEs
More Total CVEs than 100% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
8.2
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
0.3%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Delta Electronics, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 15, 2018
8 years ago
Most Recent CVE
Apr 24, 2026
93 days ago

Self-Reporting Analysis

Of all the CVEs published by Delta Electronics, Inc. as a CNA, 78.3% affect products that Delta Electronics, Inc. develops as a vendor.

78.3%
21.7%
Self-reported: 47 (78.3%)
Third-party: 13 (21.7%)

Of all the CVEs published that affect products developed by Delta Electronics, Inc., 15.8% are self-published by Delta Electronics, Inc. as a CNA.

15.8%
84.2%
Self-published: 47 (15.8%)
Other CNAs: 250 (84.2%)

Products(66 total)

Top CVEs

Signals from CVEs in this vendor scope (297 CVEs).

297 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-38406HIGH
Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in multiple out-of-bound
Sep 17, 20217.892YESNO
CVE-2018-10594CRITICAL
Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPSimulator EH2, EH3, ES2, SE, SS2 and AHSIM_5x0, AHSIM_5x1) ut
Jun 26, 20189.883NOYES
CVE-2023-1133CRITICAL
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service acc
Mar 27, 20239.868NOYES
CVE-2024-4548CRITICAL
An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the '~
May 6, 20249.852NOYES
CVE-2021-32955CRITICAL
Delta Electronics DIAEnergie Version 1.7.5 and prior allows unrestricted file uploads, which may allow an attacker to remotely execute code.
Aug 30, 20219.848NONO
CVE-2022-41772CRITICAL
Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters used in path traversal. This path traversal could result in r
Oct 31, 20229.844NONO
CVE-2022-41657CRITICAL
Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized into memory to be used in file operation application progra
Oct 31, 20229.841NONO
CVE-2022-41133HIGH
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in GetDIAE_line_message_settingsListParameters. A low-privileged authen
Oct 27, 20228.841NONO
CVE-2022-43775CRITICAL
The HICT_Loop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system.
Oct 26, 20229.841NONO
CVE-2022-1366CRITICAL
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerChart.ashx. This allows an attacker to inject arbitrary SQL
May 2, 20229.841NONO
View all 297 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products297 CVEs
11%
61%
28%
Severity distribution among all CVEs352,713 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local124 (41.8%)
Network172 (57.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (0.3%)
Attack Complexity
Low295 (99.3%)
High2 (0.7%)
Unknown0 (0.0%)
User Interaction
None149 (50.2%)
Unknown0 (0.0%)
Required148 (49.8%)
Privileges Required
Low56 (18.9%)
High6 (2.0%)
None235 (79.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (297 CVEs).

CISA KEV
1 CVE
0.3% of CVEs· 99th percentile
Metasploit
3 CVEs
1.0% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
0.3% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Delta Electronics, Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Delta Electronics, Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Delta Electronics, Inc.'s Products

View all 7 CNAs →

Top CWEs