Junglewise Threat Intelligence

CVE-2026-5726: Delta Electronics ASDA-Soft stack-based buffer overflow

CVE-2026-5726 · Severity: high · CVSS 7.8 · Published 2026-04-08

Vendors: Deltaww.

Executive brief

Delta Electronics ASDA-Soft, a configuration tool used for industrial servo drives, is vulnerable to a memory corruption flaw. An attacker could exploit this by tricking a user into opening a specially crafted file, potentially leading to a complete system takeover or service disruption. This could impact industrial operations by allowing unauthorized changes to motor drive configurations or disabling the management software.

Technical details

A stack-based buffer overflow (CWE-121) exists in Delta Electronics ASDA-Soft versions 7.2.2.0 and prior. The vulnerability is triggered when the application processes a malformed file or input, leading to an out-of-bounds write (CWE-787) on the stack. While the attack vector is local, it requires user interaction (UI:R), such as opening a malicious project file. Successful exploitation can result in arbitrary code execution with the privileges of the application or a complete application crash. Users are advised to update to version 7.2.6.0 or later to mitigate this risk.

Affected products

  • Delta Electronics (DeltaWW) ASDA-Soft <= 7.2.2.0

Timeline

  • 2026-04-07: disclosed
  • 2026-04-08: advisory

References