Executive brief
The Delta Electronics AS320T, a programmable logic controller (PLC) used in industrial automation, contains a critical security flaw. An attacker can exploit this vulnerability by sending a specially crafted file name to the device, potentially allowing them to take full control of the controller. This could lead to unauthorized changes in industrial processes, equipment damage, or complete operational shutdowns.
Technical details
A stack-based buffer overflow (CWE-121) exists in the Delta Electronics AS320T PLC firmware. The vulnerability is caused by a failure to validate the length of input strings used for file names before copying them into a fixed-size stack buffer. A remote, unauthenticated attacker can exploit this over the network by providing an oversized file name string. Successful exploitation can lead to arbitrary code execution or a denial-of-service (DoS) condition. The issue is addressed in firmware version 1.16.
Affected products
- Delta Electronics AS320T firmware up to (excluding) 1.16
Timeline
- 2026-04-24: disclosed
- 2026-04-24: advisory