CVE-2025-15358

7.5

Delta Electronics · DVP-12SE11T

A vulnerability in the Delta Electronics DVP-12SE11T controller allows unauthenticated attackers to cause a denial of service via improper input validation.

Executive summary

An unauthenticated remote denial of service vulnerability exists in the Delta Electronics DVP-12SE11T, posing a significant risk to operational availability.

Vulnerability

This vulnerability is caused by improper input validation (CWE-20), which allows an unauthenticated attacker to send crafted packets to the device, resulting in a denial of service condition.

Business impact

The exploitation of this flaw can lead to the loss of availability for the affected industrial controller, potentially disrupting critical operations or automated processes. With a CVSS score of 7.5, this high severity vulnerability is particularly concerning in industrial environments where uptime is essential for safe and continuous operations.

Remediation

Immediate Action: Update the device firmware to version 2.16 or later as specified in the official Delta Electronics security advisory.

Proactive Monitoring: Monitor network traffic for unusual spikes or malformed packets directed toward the DVP-12SE11T and review system logs for signs of service instability or unexpected reboots.

Compensating Controls: Implement network segmentation to restrict access to the controller, ensuring it is only reachable by authorized management stations, and deploy an industrial firewall to inspect and filter potentially malicious traffic.

Exploitation status

Public Exploit Available: No — exploit_available (false).

Analyst recommendation

The risk posed by this denial of service vulnerability is high due to the potential for remote, unauthenticated exploitation. Organizations utilizing the Delta Electronics DVP-12SE11T must prioritize the application of the firmware update to version 2.16 to ensure the continued stability and availability of their infrastructure.

More Delta Electronics CVEs

Sources

Originally found and disclosed by Nhan Nguyen, Hoa X. Nguyen, and Tue Lam of Unit 515 from OPSWAT, per the CVE Program record.