PT-2024-28154 · Delta Electronics · Delta Electronics Dvw-W02W2-E2
Quentin Kaiser
·
Published
2024-04-16
·
Updated
2025-12-05
·
CVE-2024-3871
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Delta Electronics DVW-W02W2-E2 versions 2.5.2 and earlier
Description
The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users, which implements features affected by command injections and stack overflows. Successful exploitation of these flaws would allow remote attackers to gain remote code execution with elevated privileges on the affected devices. The interface's features, such as access control lists management and WPS pin setup, are vulnerable to these attacks.
Recommendations
For Delta Electronics DVW-W02W2-E2 versions 2.5.2 and earlier, consider disabling the web administration interface until a patch is available. Restrict access to the vulnerable features, such as access control lists management and WPS pin setup, to minimize the risk of exploitation. Avoid using the web administration interface for critical operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Command Injection
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Delta Electronics Dvw-W02W2-E2