CVE-2025-58320
7.3Delta Electronics · DIALink
Delta Electronics DIALink contains a directory traversal vulnerability that allows unauthenticated attackers to bypass authentication mechanisms.
Executive summary
A critical path traversal vulnerability in Delta Electronics DIALink allows unauthenticated attackers to bypass security controls, posing a significant risk of unauthorized access.
Vulnerability
The application is susceptible to a directory traversal flaw (CWE-22) that permits unauthenticated remote attackers to bypass authentication. By manipulating file paths, an attacker can access restricted directories or bypass security checks without providing valid credentials.
Business impact
Successful exploitation allows an unauthorized party to circumvent authentication, potentially leading to full system compromise or unauthorized data access. With a CVSS score of 7.3, this high severity vulnerability indicates a substantial risk of service disruption and loss of confidentiality, necessitating immediate attention to prevent potential exploitation of industrial control systems.
Remediation
Immediate Action: Upgrade all instances of Delta Electronics DIALink to version 1.8.0.0 or later to resolve the underlying directory traversal flaw.
Proactive Monitoring: Review system access logs for suspicious path traversal patterns or unauthorized attempts to access sensitive configuration files.
Compensating Controls: Implement network segmentation and utilize a Web Application Firewall to block requests containing directory traversal sequences directed at the DIALink interface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for unauthenticated access to critical infrastructure software, administrators must treat this vulnerability as a priority. Applying the vendor-supplied update to version 1.8.0.0 is the only effective way to neutralize this risk, and it should be performed during the next maintenance window or immediately if the affected system is internet-facing.
More Delta Electronics CVEs
Sources
Originally found and disclosed by Independent researcher Rangin Sima (Kamel), per the CVE Program record.