CVE-2026-1950
9.8Delta · Electronics AS320T
A stack-based buffer overflow in the Delta Electronics AS320T file name handling allows for potential remote code execution.
Executive summary
A critical stack-based buffer overflow in the Delta Electronics AS320T allows unauthenticated remote attackers to potentially execute arbitrary code via file name manipulation.
Vulnerability
The software fails to perform proper length validation on file name inputs, resulting in a stack-based buffer overflow (CWE-121). An unauthenticated attacker can exploit this flaw remotely to crash the system or execute arbitrary code.
Business impact
This vulnerability carries a CVSS score of 9.8, indicating the highest level of urgency. Successful exploitation can lead to full system compromise, resulting in a total loss of control over the affected hardware and potential access to sensitive operational data.
Remediation
Immediate Action: Upgrade the device firmware to version 1.16 or later as per the vendor's security instructions.
Proactive Monitoring: Monitor for abnormal process behavior or unexpected reboots that may indicate exploitation attempts targeting file system operations.
Compensating Controls: Deploy network-level traffic inspection to detect and block malformed packets containing excessively long file names before they reach the device.
Exploitation status
Public Exploit Available: No (unknown)
Analyst recommendation
The risk posed by this buffer overflow is extreme, and it must be addressed with the highest priority. Administrators should proceed with firmware updates to version 1.16 immediately, ensuring that all devices are brought into a secure state to mitigate the threat of remote code execution.