CVE-2022-1377: Deltaww Diaenergie
Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_rltHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Affected products
- Deltaww Diaenergie: before 1.8.02.004 (fixed in 1.8.02.004)
Published 2022-05-02. Last modified 2026-06-17.