← Back to browse · API

CVE-2024-4548

Severity
CRITICAL
CVSS
9.8
EPSS
0.29425
Risk score
49.5
CISA KEV
No
PoC
No
Published
2024-05-06
Modified
2024-08-01
First seen
2026-08-08
Aliases
EUVD-2024-44160, GHSA-M7WW-C868-PGPQ
Products
Delta Electronics:DIAEnergie 0 ≤1.10.1.8610
Sources
euvd EUVD-2024-44160

Description

An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field.

References