Executive brief
The Delta Electronics AS320T, a programmable logic controller (PLC) used in industrial automation, contains a vulnerability involving undocumented hidden functionality. An attacker can exploit this to cause a denial of service, potentially halting industrial processes and disrupting operations. In some assessments, this flaw is also considered to pose a risk to data confidentiality and system integrity.
Technical details
The Delta Electronics AS320T PLC firmware (prior to version 1.16) contains hidden functionality (CWE-912) in the form of an undocumented subfunction. This vulnerability can be triggered over the network without authentication. While primarily reported as a denial of service (DoS) vector, vendor assessments suggest the flaw may also allow for unauthorized access to or modification of system data (C/I/A impact). Exploitation allows a remote attacker to disrupt the device's availability, effectively crashing the controller. Users are advised to update to firmware version 1.16 or later.
Affected products
- Delta Electronics AS320T firmware versions up to (excluding) 1.16
Timeline
- 2026-04-24: disclosed
- 2026-04-24: advisory: Vendor advisory Delta-PCSA-2026-00006 published