CVE-2025-58317: File Parsing Memory Corruption in CNCSoft-G2
Published Sep 24, 2025
·Updated
Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.
Affected Software
2 affected components
Delta Electronics CNCSoft-G2
Deltaww Cncsoft-g2<2.1.0.34
Remediation
Information
Download and update to: v2.1.0.34 or later
Event History
Sep 24, 2025
CVE Published
via MITRE·06:38 AM
Data Sourced
via MITRE·06:38 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-58317?
CVE-2025-58317 is classified as a high-severity vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2025-58317?
To mitigate CVE-2025-58317, ensure that you are using the latest version of Delta Electronics CNCSoft-G2 that includes security patches.
3
What types of attacks are possible with CVE-2025-58317?
CVE-2025-58317 can be exploited through specially crafted malicious files that execute arbitrary code.
4
Which software is affected by CVE-2025-58317?
CVE-2025-58317 affects Delta Electronics CNCSoft-G2 software.
5
Are there any workarounds for CVE-2025-58317?
One workaround for CVE-2025-58317 is to avoid opening untrusted or suspicious files within Delta Electronics CNCSoft-G2.