← Vulnerability feed

Vulnerability record · CVE-2022-2660 · published 13 December 2022

CVE-2022-2660: Deltaww dialink hard-coded credentials vulnerability

Deltaww · Dialink

Delta Industrial Automation DIALink versions 1.4.0.0 and prior are vulnerable to the use of a hard-coded cryptographic key which could allow an attacker to decrypt sensitive data and compromise the machine.

7.5 CVSS 3.1 High EPSS 0.63% · top 51.8% CWE-321 · CWE-321CWE-798 · Hard-coded credentials
7.5CVSS 3.1 base score
0.63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Delta Industrial Automation DIALink versions 1.4.0.0 and prior are vulnerable to the use of a hard-coded cryptographic key which could allow an attacker to decrypt sensitive data and compromise the machine.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.cisa.gov/uscert/ics/advisories/icsa-22-235-02 Third Party AdvisoryUS Government Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-22-235-02 Third Party AdvisoryUS Government Resource

Track CVE-2022-2660 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-58321Deltaww dialink path traversal vulnerabilityDelta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.EPSS 1.3%7.8CVE-2021-38416Deltaww dialink uncontrolled search path element vulnerabilityDelta Electronics DIALink versions 1.2.4.0 and prior insecurely loads libraries, which may allow an attacker to use DLL hijacking and takeover the sy…EPSS 0.26%7.8CVE-2021-38420Deltaww dialink uncontrolled search path element vulnerabilityDelta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged user accounts, which may allow …EPSS 0.23%7.8CVE-2021-38422Deltaww dialink cleartext storage of sensitive data vulnerabilityDelta Electronics DIALink versions 1.2.4.0 and prior stores sensitive information in cleartext, which may allow an attacker to have extensive access …EPSS 0.18%7.8CVE-2021-38424Deltaww dialink csv injection vulnerabilityThe tag interface of Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to an attacker injecting formulas into the tag data. Those fo…EPSS 0.51%7.5CVE-2022-2969Deltaww dialink path traversal vulnerabilityDelta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4 uses an external input to construct a pathname intended to identify a file or d…EPSS 2.3%7.3CVE-2025-58320Deltaww dialink path traversal vulnerabilityDelta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.EPSS 14%5.9CVE-2021-38418Deltaww dialink cleartext transmission vulnerabilityDelta Electronics DIALink versions 1.2.4.0 and prior runs by default on HTTP, which may allow an attacker to be positioned between the traffic and pe…EPSS 0.57%

Source: NIST National Vulnerability Database (record CVE-2022-2660), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.