ZDI-25-101: (0Day) Delta Electronics ISPSoft DVP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published Mar 3, 2025
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics ISPSoft. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
Affected Software
1 affected component
Delta Electronics ISPSoft
Event History
Mar 3, 2025
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-25-101?
The severity of ZDI-25-101 is rated as critical due to the potential for remote code execution.
2
How do I fix ZDI-25-101?
To fix ZDI-25-101, update Delta Electronics ISPSoft to the latest version provided by the vendor.
3
Who is affected by ZDI-25-101?
Users of Delta Electronics ISPSoft are affected by ZDI-25-101.
4
What exploitation method is used in ZDI-25-101?
ZDI-25-101 requires user interaction, such as visiting a malicious page or opening a malicious file.
5
What is the impact of ZDI-25-101?
ZDI-25-101 allows remote attackers to execute arbitrary code on affected installations.