PT-2026-5909 · Unknown · Delta Course Automation
Published
2026-02-04
·
Updated
2026-02-09
·
CVE-2025-5329
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Delta Course Automation versions through 04022026
Description
Delta Course Automation is susceptible to a SQL Injection issue due to improper neutralization of special elements used in an SQL command. This allows for potential unauthorized database access. The vendor was contacted regarding this issue but did not respond. No information is available regarding the number of potentially affected devices or any real-world exploitation of this issue. The vulnerability allows full database access without authentication.
Recommendations
Versions prior to 04022026 should be updated.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Delta Course Automation