CVE-2025-58317

7.8

Delta Electronics · CNCSoft-G2

Delta Electronics CNCSoft-G2 is vulnerable to a stack-based buffer overflow due to improper validation of user-supplied files, potentially allowing arbitrary code execution.

Executive summary

A critical stack-based buffer overflow in Delta Electronics CNCSoft-G2 could allow an attacker to execute arbitrary code when a user opens a malicious file.

Vulnerability

The software suffers from a stack-based buffer overflow (CWE-121) triggered by the lack of proper validation on user-supplied files. An attacker can exploit this by enticing a user to open a specially crafted file, resulting in code execution within the context of the current process.

Business impact

The successful exploitation of this vulnerability poses a significant risk to operational integrity, as it permits arbitrary code execution on systems running CNCSoft-G2. Given the CVSS score of 7.8, this flaw represents a high-severity risk that could lead to unauthorized system control, potential loss of intellectual property, or disruption of manufacturing processes.

Remediation

Immediate Action: Update Delta Electronics CNCSoft-G2 to version 2.1.0.34 or later to apply the necessary security patches.

Proactive Monitoring: Monitor system logs for unusual process activity or crashes associated with file parsing operations in the CNCSoft-G2 environment.

Compensating Controls: Implement endpoint protection solutions and restrict the execution of untrusted files within the industrial control environment until the update is deployed.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a serious risk to the stability and security of the affected CNC software. IT and security teams should prioritize the deployment of version 2.1.0.34 across all affected endpoints immediately to eliminate the underlying stack-based buffer overflow condition.

More Delta Electronics CVEs

Sources

Originally found and disclosed by Natnael Samson working with Trend Micro Zero Day Initiative, with CISA (coordinator), per the CVE Program record.