CVE-2024-28029: Deltaww Diaenergie

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality.

Affected products

  • Deltaww Diaenergie: before 1.10.00.005 (fixed in 1.10.00.005)

Published 2024-03-21. Last modified 2026-06-17.