ZDI-25-976: Delta Electronics ASDA-Soft PAR File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics ASDA-Soft. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-62580.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-976?
ZDI-25-976 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix ZDI-25-976?
To mitigate ZDI-25-976, users should update Delta Electronics ASDA-Soft to the latest version that addresses this vulnerability.
What is required for an attacker to exploit ZDI-25-976?
An attacker needs user interaction, such as visiting a malicious page or opening a malicious file, to exploit ZDI-25-976.
What types of systems are affected by ZDI-25-976?
ZDI-25-976 affects installations of Delta Electronics ASDA-Soft software.
Can ZDI-25-976 be remotely executed?
Yes, ZDI-25-976 allows remote attackers to execute arbitrary code if the user interacts with the malicious content.