Description
The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This interface implements multiple features that are affected by command injections and stack overflows vulnerabilities. Successful exploitation of these flaws would allow remote unauthenticated attackers to gain remote code execution with elevated privileges on the affected devices. This issue affects DVW-W02W2-E2 through version 2.5.2.
References (1)
Core 1
Core References
Various Sources
https://onekey.com/
Scores
CVSS v3
9.8
EPSS
0.0281
EPSS Percentile
86.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-120
CWE-77
Status
published
Products (1)
Deltra Electronics/DVW-W02W2-E2
< 2.5.2
Published
Apr 16, 2024
Tracked Since
Feb 18, 2026