Impact
The DVP80ES300T firmware contains a flaw where array indices are not properly validated, allowing an out‑of‑range index to be supplied. This improper validation can corrupt memory and destabilize the device, potentially resulting in crashes or other unexpected behavior. The weakness corresponds to a classic bounds‑check bypass (CWE‑129).
Affected Systems
All DeltaWatt DVP80ES300T appliances running firmware versions earlier than v1.10 are affected. The vendor explicitly lists the entire appliance line as vulnerable and recommends upgrading to firmware v1.10 or newer.
Risk and Exploitability
The vulnerability has a CVSS score of 7.5, indicating high severity. No EPSS value is available, so the current likelihood of exploitation remains uncertain, but the lack of bounds checking invites attackers who can send crafted requests locally or through exposed interfaces. The flaw is not listed in the CISA KEV catalog. An attacker with privilege or direct access could trigger memory corruption that would interrupt normal device operation and could be used to force a reboot or to destabilize services.
OpenCVE Enrichment