Junglewise Threat Intelligence

CVE-2026-1949: Delta Electronics AS320T stack buffer overflow in web service

CVE-2026-1949 · Severity: critical · CVSS 9.8 · Published 2026-04-24

Technologies: Deltaww As320t Firmware, Deltaww As320t. Vendors: Deltaww, Delta Electronics.

Executive brief

A critical vulnerability exists in the Delta Electronics AS320T, a programmable logic controller (PLC) used in industrial automation. An attacker can remotely exploit a flaw in the device's web management interface to gain full control over the system. This could lead to unauthorized access to industrial processes, data theft, or a complete shutdown of operations.

Technical details

A stack-based buffer overflow vulnerability (CWE-131) exists in the web service component of Delta Electronics AS320T devices. The flaw is located within the GET/PUT request handler, where the application incorrectly calculates buffer sizes on the stack. A remote, unauthenticated attacker can exploit this by sending specially crafted HTTP requests over the network. Successful exploitation can lead to arbitrary code execution with high privileges, potentially resulting in a full system compromise. The vulnerability is addressed in firmware version 1.16.

Affected products

  • Delta Electronics AS320T firmware up to (excluding) 1.16

Timeline

  • 2026-04-24: disclosed
  • 2026-04-24: advisory: Vendor advisory Delta-PCSA-2026-00006 released

References

Related threats