Critical Bugs Spotted in Delta Industrial PLCs
These articles are AI-generated summaries. Please check the original sources for full details.
Critical Vulnerabilities in Delta Electronics PLCs
Researchers discovered four vulnerabilities in the DVP-12SE11T PLC, a popular controller in Asian industrial sectors like water treatment and food processing. Three of these vulnerabilities received a critical CVSS score above 9.0, highlighting significant risk.
While Delta released a firmware fix in early January 2026, the nature of PLCs – often running 24/7 and deeply embedded in OT networks – means patching may be delayed or impossible for many organizations. This discrepancy between ideal security practices and operational realities creates a substantial window of vulnerability, potentially leading to physical damage, injury, or even death due to compromised control systems.
Key Insights
- CVSS Scores: The identified vulnerabilities range from 7.1 to 9.8 on the Common Vulnerability Scoring System (CVSS) in 2025.
- OT Network Segmentation: The principle of “defense in depth” suggests PLCs should be isolated, but unencrypted and unauthenticated communications can bypass these defenses.
- APT Threat Actors: China-based threat actors like Volt Typhoon, UNC3886, and APT41 are considered likely candidates for targeting OT systems, given their regional interests and tactics.
Practical Applications
- Use Case: Water treatment facilities using Delta PLCs could experience disruption of service or contamination if compromised.
- Pitfall: Delaying patching due to operational constraints leaves systems vulnerable to exploitation, even with available fixes.
References:
Continue reading
Next article
Vulnerabilities Surge, But Messy Reporting Blurs Picture
Related Content
cPanel and WHM Patch Critical Vulnerabilities to Prevent RCE and Privilege Escalation
cPanel and WHM released patches for three vulnerabilities, including two CVSS 8.8 flaws, to prevent arbitrary code execution and privilege escalation.
Picklescan Bugs Allow Malicious PyTorch Models to Evade Scans and Execute Code
Three critical Picklescan vulnerabilities (CVSS 9.3) enable malicious PyTorch models to bypass scans and execute arbitrary code.
Microsoft Patches 56 Flaws, Including Actively Exploited Privilege Escalation Bug
Microsoft addressed 56 Windows security vulnerabilities in December 2025, including an actively exploited privilege escalation flaw (CVE-2025-62221) with a CVSS score of 7.8.