Description
DVP80ES3 with Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability.
Published: 2026-07-01
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an improper enforcement of message integrity during transmission, which can allow an attacker to tamper with or forge messages sent over the device’s communication channel. If an attacker can modify command or data packets, they could cause the device to execute unauthorized actions, thereby compromising its confidentiality, integrity, and availability. The weakness maps to CWE-924, which describes insufficient protection against unauthorized message alteration.

Affected Systems

The vendor responsible for the vulnerability is DeltaWaw, specifically the DVP80ES3 device. Firmware versions prior to v01.08.10 are affected and have not applied the necessary integrity checks in their communication stack.

Risk and Exploitability

The CVSS base score of 7.5 indicates this is a high severity issue. An EPSS score is not available, so the current exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. The documentation does not explicitly state the attack vector, but as the weakness involves the message integrity of a communication channel, it likely requires proximity to the network or physical control of the device’s communication interface, or else the attacker must compromise the network that provides that channel. Once the appropriate conditions are met, an attacker could alter transmitted data to influence device behaviour. Updating to firmware v01.08.10 or later mitigates the risk.

Generated by OpenCVE AI on July 1, 2026 at 12:51 UTC.

Remediation

Vendor Solution

Users are recommended to update the device firmware to v01.08.10 or later.


OpenCVE Recommended Actions

  • Apply the DeltaWaw firmware update to v01.08.10 or later.
  • Limit or block the device’s external communication channel from untrusted sources to reduce exposure to tampering attempts.
  • Monitor the device’s communication logs for anomalous message patterns that might indicate an integrity attack.

Generated by OpenCVE AI on July 1, 2026 at 12:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Description DVP80ES3 with Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability.
Title DVP80ES3 Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability
First Time appeared Deltaww
Deltaww dvp80es3
Weaknesses CWE-924
CPEs cpe:2.3:a:deltaww:dvp80es3:*:*:*:*:*:*:*:*
Vendors & Products Deltaww
Deltaww dvp80es3
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Deltaww Dvp80es3
cve-icon MITRE

Status: PUBLISHED

Assigner: Deltaww

Published:

Updated: 2026-07-01T12:21:28.074Z

Reserved: 2026-06-18T05:22:53.986Z

Link: CVE-2026-12576

cve-icon Vulnrichment

Updated: 2026-07-01T12:21:24.324Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T14:00:06Z

Weaknesses
  • CWE-924

    Improper Enforcement of Message Integrity During Transmission in a Communication Channel