PT-2024-28154 · Delta Electronics · Delta Electronics Dvw-W02W2-E2

Quentin Kaiser

·

Published

2024-04-16

·

Updated

2025-12-05

·

CVE-2024-3871

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Delta Electronics DVW-W02W2-E2 versions 2.5.2 and earlier
Description The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users, which implements features affected by command injections and stack overflows. Successful exploitation of these flaws would allow remote attackers to gain remote code execution with elevated privileges on the affected devices. The interface's features, such as access control lists management and WPS pin setup, are vulnerable to these attacks.
Recommendations For Delta Electronics DVW-W02W2-E2 versions 2.5.2 and earlier, consider disabling the web administration interface until a patch is available. Restrict access to the vulnerable features, such as access control lists management and WPS pin setup, to minimize the risk of exploitation. Avoid using the web administration interface for critical operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Command Injection

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-3871
ZDI-25-1026
ZDI-25-1037

Affected Products

Delta Electronics Dvw-W02W2-E2