CVE-2026-3631

7.5

Delta Electronics · COMMGR2

Delta Electronics COMMGR2 is susceptible to a buffer over-read vulnerability that can be triggered by an unauthenticated attacker to cause a denial of service.

Executive summary

A critical buffer over-read vulnerability in Delta Electronics COMMGR2 allows unauthenticated attackers to trigger a denial of service condition.

Vulnerability

The software contains an out-of-bounds read vulnerability (CWE-125) within its communication management components. An unauthenticated remote attacker can exploit this flaw to cause the application to crash, resulting in a denial of service.

Business impact

Successful exploitation of this vulnerability results in a denial of service, which can disrupt industrial communication processes and operational workflows. Given the CVSS score of 7.5, this high-severity flaw represents a significant risk to availability, particularly in environments where COMMGR2 is critical for system connectivity and data exchange.

Remediation

Immediate Action: Upgrade Delta Electronics COMMGR2 to version 2.11.1 or later as specified in the vendor security advisory.

Proactive Monitoring: Monitor system logs and network traffic for unusual patterns or frequent application restarts that may indicate attempted exploitation.

Compensating Controls: Deploy network-level access controls to restrict access to the COMMGR2 service to authorized IP addresses only, reducing the attack surface.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The severity of this denial of service vulnerability necessitates prompt action to maintain operational integrity. Administrators should prioritize the deployment of the vendor-provided update to version 2.11.1 to eliminate the risk of service disruption.

More Delta Electronics CVEs

Sources

Originally found and disclosed by Tenable, per the CVE Program record.