Impact
The DVP80ES3 device has an improperly implemented security check (CWE-358) that permits an attacker to bypass the standard privilege restrictions, potentially allowing unauthorized privileged operations on the device.
Affected Systems
This vulnerability affects DeltaWw’s DVP80ES3 product. Firmware versions prior to 01.10.00 are susceptible; the vendor recommends upgrading to firmware version 01.10.00 or later.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity. The EPSS score is <1% (approximately 0.25%), indicating a low but nonzero exploitation probability. Because the flaw is not listed in CISA’s KEV catalog but involves a missing or weak security check, it is inferred that attackers who can communicate with the device—such as through a management interface or open network port—might be able to exploit it. Organizations should treat this as a priority flaw and address it promptly.
OpenCVE Enrichment