Executive brief
A critical security vulnerability exists in Delta Electronics AS320T programmable logic controllers (PLCs), which are used in industrial automation. An attacker can remotely exploit this flaw to gain full control over the device, potentially leading to unauthorized process changes, data theft, or complete operational shutdown. This issue is caused by the device failing to properly limit the size of directory names it processes.
Technical details
A stack-based buffer overflow (CWE-121) exists in the Delta Electronics AS320T PLC firmware. The vulnerability is caused by a lack of bounds checking when processing directory names, allowing a buffer to be overwritten if a specially crafted, overly long string is provided. This can be exploited over the network without any user interaction or prior authentication. Successful exploitation could lead to remote code execution (RCE) or a complete system crash (DoS). The issue is addressed in firmware version 1.12.
Affected products
- Delta Electronics AS320T firmware versions up to (excluding) 1.12
Timeline
- 2026-04-24: disclosed
- 2026-04-24: advisory
- 2026-05-11: other: NVD initial analysis completed