CVE-2025-58320

7.3

Delta Electronics · DIALink

Delta Electronics DIALink contains a directory traversal vulnerability that allows unauthenticated attackers to bypass authentication mechanisms.

Executive summary

A critical path traversal vulnerability in Delta Electronics DIALink allows unauthenticated attackers to bypass security controls, posing a significant risk of unauthorized access.

Vulnerability

The application is susceptible to a directory traversal flaw (CWE-22) that permits unauthenticated remote attackers to bypass authentication. By manipulating file paths, an attacker can access restricted directories or bypass security checks without providing valid credentials.

Business impact

Successful exploitation allows an unauthorized party to circumvent authentication, potentially leading to full system compromise or unauthorized data access. With a CVSS score of 7.3, this high severity vulnerability indicates a substantial risk of service disruption and loss of confidentiality, necessitating immediate attention to prevent potential exploitation of industrial control systems.

Remediation

Immediate Action: Upgrade all instances of Delta Electronics DIALink to version 1.8.0.0 or later to resolve the underlying directory traversal flaw.

Proactive Monitoring: Review system access logs for suspicious path traversal patterns or unauthorized attempts to access sensitive configuration files.

Compensating Controls: Implement network segmentation and utilize a Web Application Firewall to block requests containing directory traversal sequences directed at the DIALink interface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for unauthenticated access to critical infrastructure software, administrators must treat this vulnerability as a priority. Applying the vendor-supplied update to version 1.8.0.0 is the only effective way to neutralize this risk, and it should be performed during the next maintenance window or immediately if the affected system is internet-facing.

More Delta Electronics CVEs

Sources

Originally found and disclosed by Independent researcher Rangin Sima (Kamel), per the CVE Program record.