← All Advisories

Delta Electronics AS320T Stack-Based Buffer Overflow Due to Missing Directory Name Length Check, Enabling Unauthenticated Remote Code Execution

Last refreshed2026-09-28

Status: UPDATED  |  Advisory ID: CVE-2026-1951

Key Details

CVECVE-2026-1951
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-06-17
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsdeltaww as320t_firmware
Classified asCWE-121 (Stack-based Buffer Overflow)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
deltawwas320t_firmware
SubsystemsGeneral OT
SectorsMultiple

What to Know

Delta Electronics AS320T has no checking of the length of the buffer with the directory name

vulnerability.

What to Do

Monitor deltaww's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-1951
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-1951
Vendor advisoryhttps://filecenter.deltaww.com/news/download/doc/Delta-PCSA-2026-00006_AS320T%20Multiple%20vulnerabilities%20(CVE-2026-1949,%201950,%201951,%201952).pdf