Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-Based buffer overflow vulnerability that could allow an attacker to leverage debugging logic to execute arbitrary code when parsing CBDGL file.

Project Subscriptions

Vendors Products
Deltaww Subscribe
Ispsoft Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2025-12683 Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-Based buffer overflow vulnerability that could allow an attacker to leverage debugging logic to execute arbitrary code when parsing CBDGL file.
Fixes

Solution

Download and update to: v3.21 or later


Workaround

No workaround given by the vendor.

History

Mon, 25 Aug 2025 03:30:00 +0000


Mon, 25 Aug 2025 03:15:00 +0000


Fri, 16 May 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Deltaww
Deltaww ispsoft
Weaknesses CWE-787
CPEs cpe:2.3:a:deltaww:ispsoft:*:*:*:*:*:*:*:*
Vendors & Products Deltaww
Deltaww ispsoft

Wed, 30 Apr 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Apr 2025 07:45:00 +0000

Type Values Removed Values Added
Description Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-Based buffer overflow vulnerability that could allow an attacker to leverage debugging logic to execute arbitrary code when parsing CBDGL file.
Title ISPSoft File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Deltaww

Published:

Updated: 2025-08-25T02:57:29.339Z

Reserved: 2025-01-09T03:48:26.774Z

Link: CVE-2025-22882

cve-icon Vulnrichment

Updated: 2025-04-30T13:05:07.988Z

cve-icon NVD

Status : Modified

Published: 2025-04-30T08:15:31.360

Modified: 2025-08-25T03:15:36.803

Link: CVE-2025-22882

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses