Junglewise Threat Intelligence

CVE-2025-62582: Delta Electronics DIAView missing authentication for critical function

CVE-2025-62582 · Severity: critical · CVSS 9.8 · Published 2026-01-16

Technologies: Delta Electronics DIAView. Vendors: Delta Electronics.

Executive brief

Delta Electronics DIAView, an industrial SCADA software used for monitoring and controlling manufacturing processes, contains a critical security flaw. This vulnerability allows unauthorized individuals to access sensitive system functions without providing any login credentials. An attacker could exploit this to disrupt industrial operations, steal proprietary data, or gain full control over the management system.

Technical details

Delta Electronics DIAView versions prior to 4.4.0 are affected by a missing authentication vulnerability (CWE-306) in critical functional components. The flaw allows a remote, unauthenticated attacker to execute sensitive commands or access restricted data over the network without any user interaction. Given the CVSS score of 9.8, the vulnerability likely permits full compromise of confidentiality, integrity, and availability. Users are advised to update to DIAView version 4.4.0 or later to mitigate these risks.

Affected products

  • Delta Electronics DIAView versions up to (excluding) 4.4.0

Timeline

  • 2026-01-15: disclosed
  • 2026-01-16: advisory: NVD published date

References

Related threats