← Vulnerability feed

Vulnerability record · CVE-2021-38428 · published 3 November 2021

CVE-2021-38428: Deltaww dialink cross-site scripting vulnerability

Deltaww · Dialink

Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API schedule, which may allow an attacker to remotely execute code.

4.8 CVSS 3.1 Medium EPSS 11% · top 4.1% CWE-79 · Cross-site scripting
4.8CVSS 3.1 base score, v2 3.5
11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API schedule, which may allow an attacker to remotely execute code.

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://us-cert.cisa.gov/ics/advisories/icsa-21-294-02 Third Party AdvisoryUS Government Resource
https://us-cert.cisa.gov/ics/advisories/icsa-21-294-02 Third Party AdvisoryUS Government Resource

Track CVE-2021-38428 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-58321Deltaww dialink path traversal vulnerabilityDelta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.EPSS 1.3%7.8CVE-2021-38416Deltaww dialink uncontrolled search path element vulnerabilityDelta Electronics DIALink versions 1.2.4.0 and prior insecurely loads libraries, which may allow an attacker to use DLL hijacking and takeover the sy…EPSS 0.26%7.8CVE-2021-38420Deltaww dialink uncontrolled search path element vulnerabilityDelta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged user accounts, which may allow …EPSS 0.23%7.8CVE-2021-38422Deltaww dialink cleartext storage of sensitive data vulnerabilityDelta Electronics DIALink versions 1.2.4.0 and prior stores sensitive information in cleartext, which may allow an attacker to have extensive access …EPSS 0.18%7.8CVE-2021-38424Deltaww dialink csv injection vulnerabilityThe tag interface of Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to an attacker injecting formulas into the tag data. Those fo…EPSS 0.51%7.5CVE-2022-2660Deltaww dialink hard-coded credentials vulnerabilityDelta Industrial Automation DIALink versions 1.4.0.0 and prior are vulnerable to the use of a hard-coded cryptographic key which could allow an attac…EPSS 0.63%7.5CVE-2022-2969Deltaww dialink path traversal vulnerabilityDelta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4 uses an external input to construct a pathname intended to identify a file or d…EPSS 2.3%7.3CVE-2025-58320Deltaww dialink path traversal vulnerabilityDelta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.EPSS 14%

Source: NIST National Vulnerability Database (record CVE-2021-38428), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.