Description
DVP80ES300T with Improper Validation of Array Index Vulnerability
Published: 2026-07-01
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The DVP80ES300T firmware contains a flaw where array indices are not properly validated, allowing an out‑of‑range index to be supplied. This improper validation can corrupt memory and destabilize the device, potentially resulting in crashes or other unexpected behavior. The weakness corresponds to a classic bounds‑check bypass (CWE‑129).

Affected Systems

All DeltaWatt DVP80ES300T appliances running firmware versions earlier than v1.10 are affected. The vendor explicitly lists the entire appliance line as vulnerable and recommends upgrading to firmware v1.10 or newer.

Risk and Exploitability

The vulnerability has a CVSS score of 7.5, indicating high severity. No EPSS value is available, so the current likelihood of exploitation remains uncertain, but the lack of bounds checking invites attackers who can send crafted requests locally or through exposed interfaces. The flaw is not listed in the CISA KEV catalog. An attacker with privilege or direct access could trigger memory corruption that would interrupt normal device operation and could be used to force a reboot or to destabilize services.

Generated by OpenCVE AI on July 1, 2026 at 15:05 UTC.

Remediation

Vendor Solution

Users are recommended to upgrade the firmware to v1.10 or later.


OpenCVE Recommended Actions

  • Upgrade the DVP80ES300T firmware to version 1.10 or later as recommended by DeltaWatt.
  • If a firmware upgrade cannot be performed immediately, block external interfaces that allow sending index values, such as disabling web management or restricting access to management protocols from untrusted networks.
  • Continuously monitor device logs and performance for crashes, reboots, or suspicious memory activity, and apply the upgrade as soon as an exploitation attempt is detected.

Generated by OpenCVE AI on July 1, 2026 at 15:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Description DVP80ES300T with Improper Validation of Array Index Vulnerability
Title DVP80ES300T - Improper Validation of Array Index Vulnerability
Weaknesses CWE-129
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Deltaww

Published:

Updated: 2026-07-01T12:28:00.186Z

Reserved: 2026-06-30T08:45:55.964Z

Link: CVE-2026-14193

cve-icon Vulnrichment

Updated: 2026-07-01T12:27:54.845Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T15:15:04Z

Weaknesses
  • CWE-129

    Improper Validation of Array Index