Successful exploitation of these remotely exploitable vulnerabilities could allow an attacker with low privileges to gain root access or allow an unauthenticated attacker to perform remote code execution. CISA discovered a public Proof of Concept (PoC) as authored by T. Weber of CyberDanube Security Research, who reported it to Delta Electronics.
Version 1.5.0.10 of DX-2100-L1-CN, an industrial ethernet router, suffers from the vulnerabilities.
In the vulnerability, the web configuration service of the affected device contains an authenticated command injection vulnerability. It can be used to execute system commands on the operating system (OS) from the device in the context of the user “root.” If the attacker has credentials for the web service, then the device could be fully compromised.
CVE-2022-42140 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 8.8.
In addition, the affected device contains a stored cross-site scripting vulnerability in the “net diagnosis” function in the web configuration service. This can be exploited in the context of a victim’s session. An attacker could deliver a large variety of payloads that could lead to possibilities, such as remote code execution.
CVE-2023-0432 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 9.0.
The product sees use mainly in the critical manufacturing sector, and on a global basis.
An attacker with low skill level could leverage these low complexity vulnerabilities.
Taiwan-basedDelta Electronics patched this vulnerability in Version 1.5.0.12 and recommends all users update device firmware to that version or later.

