Executive brief
A critical vulnerability exists in the Delta Electronics AS320T, a programmable logic controller (PLC) used in industrial automation. An attacker can remotely exploit a flaw in the device's web management interface to gain full control over the system. This could lead to unauthorized access to industrial processes, data theft, or a complete shutdown of operations.
Technical details
A stack-based buffer overflow vulnerability (CWE-131) exists in the web service component of Delta Electronics AS320T devices. The flaw is located within the GET/PUT request handler, where the application incorrectly calculates buffer sizes on the stack. A remote, unauthenticated attacker can exploit this by sending specially crafted HTTP requests over the network. Successful exploitation can lead to arbitrary code execution with high privileges, potentially resulting in a full system compromise. The vulnerability is addressed in firmware version 1.16.
Affected products
- Delta Electronics AS320T firmware up to (excluding) 1.16
Timeline
- 2026-04-24: disclosed
- 2026-04-24: advisory: Vendor advisory Delta-PCSA-2026-00006 released