← Vulnerability feed

Vulnerability record · CVE-2024-4548 · published 6 May 2024

CVE-2024-4548: Deltaww diaenergie improper input validation vulnerability

Deltaww · Diaenergie

An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field.

9.8 CVSS 3.1 Critical EPSS 29% · top 1.9% CWE-20 · Improper input validationCWE-89 · SQL injection
9.8CVSS 3.1 base score
29%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-4548 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-4547Deltaww diaenergie improper input validation vulnerabilityA SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is sp…EPSS 1.9%9.8CVE-2024-25574Deltaww diaenergie sql injection vulnerabilitySQL injection vulnerability exists in GetDIAE_usListParameters.EPSS 8.8%9.8CVE-2022-43774Deltaww diaenergie sql injection vulnerabilityThe HandlerPageP_KID class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a…EPSS 0.75%9.8CVE-2022-43775Deltaww diaenergie sql injection vulnerabilityThe HICT_Loop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote…EPSS 21%9.8CVE-2022-3214Deltaww diaenergie hard-coded credentials vulnerabilityDelta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Versions pr…EPSS 2.0%9.8CVE-2022-1367Deltaww diaenergie sql injection vulnerabilityDelta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in Handler_TCV.ashx. This allows an at…EPSS 19%9.8CVE-2022-1369Deltaww diaenergie sql injection vulnerabilityDelta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegIND. This allows an attacker…EPSS 1.2%9.8CVE-2022-1370Deltaww diaenergie sql injection vulnerabilityDelta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadREGbyID. This allows an attacke…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2024-4548), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.