CVE-2026-12819: DVP-12SE Missing Authentication and Unauthorized Write access Vulnerability
Published Jun 30, 2026
·Updated
Delta Electronics DVP12SE PLC exposes a Modbus TCP service over a specified port without authentication or access control, permitting unauthenticated interaction with security-sensitive PLC functions.
Affected Software
1 affected component
Delta Electronics DVP12SE PLC
Event History
Jun 30, 2026
CVE Published
via MITRE·06:28 AM
Data Sourced
via MITRE·06:28 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-12819?
CVE-2026-12819 has a critical severity rating of 9.3.
2
How do I fix CVE-2026-12819?
To mitigate CVE-2026-12819, implement proper authentication mechanisms and access controls for the Modbus TCP service.
3
What are the implications of CVE-2026-12819?
CVE-2026-12819 allows unauthorized access to sensitive PLC functions, posing a significant security risk.
4
Who is affected by CVE-2026-12819?
CVE-2026-12819 affects users of the Delta Electronics DVP12SE PLC.
5
Can CVE-2026-12819 lead to further exploits?
Yes, the lack of authentication and access control in CVE-2026-12819 can lead to additional unauthorized actions and potential system compromise.