CVE-2025-58317
7.8Delta Electronics · CNCSoft-G2
Delta Electronics CNCSoft-G2 is vulnerable to a stack-based buffer overflow due to improper validation of user-supplied files, potentially allowing arbitrary code execution.
Executive summary
A critical stack-based buffer overflow in Delta Electronics CNCSoft-G2 could allow an attacker to execute arbitrary code when a user opens a malicious file.
Vulnerability
The software suffers from a stack-based buffer overflow (CWE-121) triggered by the lack of proper validation on user-supplied files. An attacker can exploit this by enticing a user to open a specially crafted file, resulting in code execution within the context of the current process.
Business impact
The successful exploitation of this vulnerability poses a significant risk to operational integrity, as it permits arbitrary code execution on systems running CNCSoft-G2. Given the CVSS score of 7.8, this flaw represents a high-severity risk that could lead to unauthorized system control, potential loss of intellectual property, or disruption of manufacturing processes.
Remediation
Immediate Action: Update Delta Electronics CNCSoft-G2 to version 2.1.0.34 or later to apply the necessary security patches.
Proactive Monitoring: Monitor system logs for unusual process activity or crashes associated with file parsing operations in the CNCSoft-G2 environment.
Compensating Controls: Implement endpoint protection solutions and restrict the execution of untrusted files within the industrial control environment until the update is deployed.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability presents a serious risk to the stability and security of the affected CNC software. IT and security teams should prioritize the deployment of version 2.1.0.34 across all affected endpoints immediately to eliminate the underlying stack-based buffer overflow condition.
More Delta Electronics CVEs
Sources
Originally found and disclosed by Natnael Samson working with Trend Micro Zero Day Initiative, with CISA (coordinator), per the CVE Program record.