Executive brief
The Delta Electronics AS228T, a programmable logic controller (PLC) used in industrial automation, contains a security flaw that allows unauthorized users to bypass authentication. An attacker could exploit this to gain control over the device, potentially disrupting industrial processes or modifying system configurations. This poses a significant risk to operational continuity and the integrity of automated production environments.
Technical details
An authentication bypass vulnerability (CWE-288) exists in the Delta Electronics AS228T PLC firmware versions 1.14 and earlier. The flaw involves an alternate path or channel that allows an attacker to circumvent standard authentication mechanisms. While the attack vector is network-based and requires no prior privileges or user interaction, the complexity is rated as high, likely due to specific timing or environmental conditions required for successful exploitation. If successful, an attacker can achieve high impacts on system integrity and availability. Users are advised to refer to Delta Electronics advisory Delta-PCSA-2026-00012 for remediation steps.
Affected products
- Delta Electronics AS228T up to and including 1.14
Timeline
- 2026-07-01: advisory: Initial disclosure by Delta Electronics and NVD publication.