Description
DVP80ES3 with Improperly Implemented Security Check for Standard vulnerability.
Published: 2026-07-01
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The DVP80ES3 device has an improperly implemented security check (CWE-358) that permits an attacker to bypass the standard privilege restrictions, potentially allowing unauthorized privileged operations on the device.

Affected Systems

This vulnerability affects DeltaWw’s DVP80ES3 product. Firmware versions prior to 01.10.00 are susceptible; the vendor recommends upgrading to firmware version 01.10.00 or later.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity. The EPSS score is <1% (approximately 0.25%), indicating a low but nonzero exploitation probability. Because the flaw is not listed in CISA’s KEV catalog but involves a missing or weak security check, it is inferred that attackers who can communicate with the device—such as through a management interface or open network port—might be able to exploit it. Organizations should treat this as a priority flaw and address it promptly.

Generated by OpenCVE AI on July 1, 2026 at 18:29 UTC.

Remediation

Vendor Solution

Users are recommended to update the device firmware to v01.10.00 or later.


OpenCVE Recommended Actions

  • Update the DVP80ES3 device firmware to version 01.10.00 or newer.
  • If an immediate firmware upgrade is not possible, restrict network access to the device so that only trusted administrators can reach it.
  • Monitor the device logs for abnormal activity or unauthorized configuration changes to detect potential exploitation attempts.

Generated by OpenCVE AI on July 1, 2026 at 18:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Description DVP80ES3 with Improperly Implemented Security Check for Standard vulnerability.
Title DVP80ES3 Improperly Implemented Security Check for Standard vulnerability
First Time appeared Deltaww
Deltaww dvp80es3
Weaknesses CWE-358
CPEs cpe:2.3:a:deltaww:dvp80es3:*:*:*:*:*:*:*:*
Vendors & Products Deltaww
Deltaww dvp80es3
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Deltaww Dvp80es3
cve-icon MITRE

Status: PUBLISHED

Assigner: Deltaww

Published:

Updated: 2026-07-01T12:35:02.947Z

Reserved: 2026-06-18T05:22:55.191Z

Link: CVE-2026-12577

cve-icon Vulnrichment

Updated: 2026-07-01T12:34:57.288Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T18:30:15Z

Weaknesses
  • CWE-358

    Improperly Implemented Security Check for Standard