Executive brief
Delta Electronics DTMSoft, a software tool used for managing industrial device configurations, is vulnerable to a security flaw when processing project files. An attacker could trick a user into opening a specially crafted file, allowing the attacker to take control of the computer and execute malicious commands. This could lead to a total compromise of the workstation used to manage industrial equipment.
Technical details
A deserialization vulnerability (CWE-502) exists in Delta Electronics DTMSoft during the parsing of project files. The root cause is the application's failure to properly validate or sanitize data before deserializing it into objects. An attacker can exploit this by providing a malicious project file to a user; if the user opens the file, the attacker can achieve arbitrary code execution with the privileges of the application. The attack vector is local, requiring user interaction to open the crafted file. According to the vendor advisory, all versions of the product are currently considered affected.
Affected products
- Delta Electronics (Deltaww) DTMSoft All versions (*)
Timeline
- 2026-06-30: advisory: Initial advisory published by Delta Electronics and NVD