CVE-2026-0975
7.8Delta Electronics · DIAView
Delta Electronics DIAView is susceptible to a command injection vulnerability, potentially allowing unauthorized system command execution.
Executive summary
A command injection vulnerability in Delta Electronics DIAView allows for potential remote code execution, posing a significant risk to industrial control environments.
Vulnerability
The software fails to properly neutralize special elements used in a command, leading to CWE-77 Command Injection. Based on the CVSS vector, this flaw can be triggered by an attacker with local access who leverages user interaction to execute arbitrary commands.
Business impact
Successful exploitation of this vulnerability could lead to total loss of confidentiality, integrity, and availability of the affected system. Given the CVSS score of 7.8, this vulnerability represents a high-severity risk, particularly in operational technology environments where unauthorized command execution can disrupt critical industrial processes or facilitate further lateral movement within the network.
Remediation
Immediate Action: Upgrade Delta Electronics DIAView to version 4.4 or later to remediate the underlying command injection flaw.
Proactive Monitoring: Review system access logs for anomalous command execution patterns or unauthorized attempts to interact with the DIAView application interface.
Compensating Controls: Restrict local access to the host machine and implement strict endpoint controls to limit the potential for user interaction with malicious inputs.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The severity of this vulnerability necessitates immediate attention, especially within industrial environments. Administrators should prioritize upgrading to version 4.4 or later to eliminate the risk of command injection, as this is the only definitive method to secure the affected software against this threat.
More Delta Electronics CVEs
Sources
Originally found and disclosed by ZDI, with CISA (coordinator), per the CVE Program record.