CVE-2025-53419

7.8

Delta Electronics · COMMGR

Delta Electronics COMMGR contains a code injection vulnerability that could allow for arbitrary code execution.

Executive summary

A code injection vulnerability in Delta Electronics COMMGR version 2.9.0 and earlier poses a significant risk of arbitrary code execution.

Vulnerability

The application is susceptible to CWE-94: Code Injection. The vulnerability requires local access and user interaction to trigger, as indicated by the CVSS vector (AV:L/UI:R).

Business impact

Successful exploitation of this flaw could allow an attacker to execute arbitrary code with the privileges of the application, potentially leading to a full system compromise. With a CVSS score of 7.8, this is categorized as a High severity vulnerability that could result in data loss, unauthorized access, and operational disruption. Organizations using COMMGR in production environments should prioritize this update to prevent potential lateral movement or system takeover.

Remediation

Immediate Action: Update the Delta Electronics COMMGR software to version 2.10.0 or later as specified by the vendor.

Proactive Monitoring: Review system access logs for unusual process execution patterns or unexpected spikes in resource utilization associated with the COMMGR utility.

Compensating Controls: Restrict local access to systems running COMMGR and ensure that only authorized users can initiate software interactions, as the vulnerability requires user interaction to exploit.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for code execution and the associated high severity score, it is imperative to mitigate this risk by applying the vendor-supplied patch. Administrators should verify their current deployment versions and schedule an update to version 2.10.0 at the earliest opportunity to eliminate the vulnerability.

More Delta Electronics CVEs

Sources

Originally found and disclosed by Guillaume Orlando working with Trend Micro Zero Day Initiative, with JosephCV of CISA (coordinator), per the CVE Program record.