Executive brief
Delta Electronics DVP12SE programmable logic controllers (PLCs), which are used to automate industrial machinery and processes, contain a security flaw where a management service is left open without a password. An attacker could remotely connect to these controllers to change settings or disrupt industrial operations. This could lead to unauthorized control of physical equipment, production downtime, or safety risks in a factory environment.
Technical details
The Delta Electronics DVP12SE PLC suffers from a missing authentication vulnerability (CWE-306) in its Modbus TCP service implementation. The device exposes a specific port that allows network-based attackers to interact with security-sensitive PLC functions without providing credentials or passing through access control mechanisms. By sending crafted Modbus TCP packets, an unauthenticated attacker can read or write to PLC registers, potentially leading to unauthorized configuration changes, process disruption, or full control over the logic execution. The vulnerability is reachable over the network and requires no user interaction.
Affected products
- Delta Electronics DVP-12SE PLC All versions
Timeline
- 2026-06-30: disclosed
- 2026-06-30: advisory