Impact
The flaw is an improper enforcement of message integrity during transmission, which can allow an attacker to tamper with or forge messages sent over the device’s communication channel. If an attacker can modify command or data packets, they could cause the device to execute unauthorized actions, thereby compromising its confidentiality, integrity, and availability. The weakness maps to CWE-924, which describes insufficient protection against unauthorized message alteration.
Affected Systems
The vendor responsible for the vulnerability is DeltaWaw, specifically the DVP80ES3 device. Firmware versions prior to v01.08.10 are affected and have not applied the necessary integrity checks in their communication stack.
Risk and Exploitability
The CVSS base score of 7.5 indicates this is a high severity issue. An EPSS score is not available, so the current exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. The documentation does not explicitly state the attack vector, but as the weakness involves the message integrity of a communication channel, it likely requires proximity to the network or physical control of the device’s communication interface, or else the attacker must compromise the network that provides that channel. Once the appropriate conditions are met, an attacker could alter transmitted data to influence device behaviour. Updating to firmware v01.08.10 or later mitigates the risk.
OpenCVE Enrichment