Junglewise Threat Intelligence

CVE-2026-1950: Delta Electronics AS320T stack overflow in file name handling

CVE-2026-1950 · Severity: critical · CVSS 9.8 · Published 2026-04-24

Technologies: Deltaww As320t Firmware, Deltaww As320t. Vendors: Deltaww, Delta Electronics.

Executive brief

The Delta Electronics AS320T, a programmable logic controller (PLC) used in industrial automation, contains a critical security flaw. An attacker can exploit this vulnerability by sending a specially crafted file name to the device, potentially allowing them to take full control of the controller. This could lead to unauthorized changes in industrial processes, equipment damage, or complete operational shutdowns.

Technical details

A stack-based buffer overflow (CWE-121) exists in the Delta Electronics AS320T PLC firmware. The vulnerability is caused by a failure to validate the length of input strings used for file names before copying them into a fixed-size stack buffer. A remote, unauthenticated attacker can exploit this over the network by providing an oversized file name string. Successful exploitation can lead to arbitrary code execution or a denial-of-service (DoS) condition. The issue is addressed in firmware version 1.16.

Affected products

  • Delta Electronics AS320T firmware up to (excluding) 1.16

Timeline

  • 2026-04-24: disclosed
  • 2026-04-24: advisory

References

Related threats