Executive brief
Delta DIAEnergie is an industrial energy management system used to monitor and control power distribution and consumption. A SQL injection vulnerability in version 1.11.00.002 allows an attacker to execute arbitrary SQL commands and potentially achieve remote code execution on the affected system, potentially compromising operational technology infrastructure and customer data.
Technical details
The vulnerability is a SQL injection flaw in Delta DIAEnergie v1.11.00.002 where insufficient input validation allows attackers to inject malicious SQL commands. The attack is remotely exploitable without requiring authentication. By crafting specially formatted requests with SQL metacharacters, an attacker can execute arbitrary SQL queries, and under certain database configurations, escalate to remote code execution. Patches are available from Delta; affected users should update to patched versions and apply network segmentation around energy management systems.
Affected products
- Delta DIAEnergie 1.11.00.002
Timeline
- 2026-08-24: disclosed