Home

Description

Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

PUBLISHED Reserved 2025-05-08 | Published 2025-06-04 | Updated 2026-03-18 | Assigner Deltaww




HIGH: 7.3CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Problem types

CWE-787 Out-of-bounds Write

Product status

Default status
unaffected

Any version before 2.1.0.27
affected

Credits

Kholoud Altookhy from Trend Micro's Zero Day Initiative reporter

CISA coordinator

References

filecenter.deltaww.com/...File Parsing Memory Corruption.pdf

cve.org (CVE-2025-47728)

nvd.nist.gov (CVE-2025-47728)

Download JSON