← All Advisories

Delta Electronics AS320T Stack-Based Buffer Overflow Due to Missing File Name Length Check, Enabling Unauthenticated Remote Code Execution

Last refreshed2026-09-28

Status: UPDATED  |  Advisory ID: CVE-2026-1950

Key Details

CVECVE-2026-1950
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-06-17
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsdeltaww as320t_firmware
Classified asCWE-121 (Stack-based Buffer Overflow)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
deltawwas320t_firmware
SubsystemsGeneral OT
SectorsMultiple

What to Know

Delta Electronics AS320T has

No checking of the length of the buffer with the file name vulnerability.

What to Do

Monitor deltaww's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-1950
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-1950
Vendor advisoryhttps://filecenter.deltaww.com/news/download/doc/Delta-PCSA-2026-00006_AS320T%20Multiple%20vulnerabilities%20(CVE-2026-1949,%201950,%201951,%201952).pdf