Delta Electronics DVP12SE PLC

Plan PatchCVSS 9.8ICS-CERT ICSA-26-181-07Jun 30, 2026
Delta ElectronicsManufacturing
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Delta Electronics DVP12SE PLC (all versions) contains critical vulnerabilities in authentication and access control (CWE-306, CWE-770) that allow unauthenticated remote attackers to issue commands, modify operational values, interfere with control logic, and alter device behavior. The PLC lacks authentication enforcement on network interfaces, permitting an attacker on the network to remotely execute arbitrary commands without credentials. Delta Electronics is developing a firmware fix but has not yet released a patched version. In the interim, the vendor recommends enabling IP filtering, implementing PLC password protection, and deploying network isolation with firewall protection.

What this means
What could happen
An attacker could remotely send commands to the PLC without any password or login, allowing them to modify setpoints, change process parameters, or halt operations entirely. This vulnerability affects industrial equipment that depends on the PLC for safe and reliable control.
Who's at risk
Manufacturing facilities and utilities operating Delta Electronics DVP12SE PLCs in any process control application (water treatment, power distribution, chemical processing, etc.). Any organization where an unauthorized change to PLC setpoints or logic could disrupt production or compromise safety should prioritize immediate workaround deployment.
How it could be exploited
An attacker on the network (or remotely if the PLC is Internet-connected) can send commands directly to the DVP12SE over the network without providing credentials. The attacker can query the PLC to download or modify ladder logic, change operational setpoints, and inject malicious control commands into running processes.
Prerequisites
  • Network access to the DVP12SE PLC (TCP/UDP ports typically used for Delta PLC communication, such as port 502 for Modbus or port 44818 for EtherCAT)
  • No authentication or valid credentials required
  • PLC must be network-reachable from the attacker's position
remotely exploitableno authentication requiredlow complexitycritical CVSS (9.8)affects control logic and operational safetyno patch available yetunauthenticated network command execution
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (1)
ProductAffected VersionsFix Status
DVP12SE PLCAll versionsNo fix yet
Remediation & Mitigation
0/6
Do now
0/4
WORKAROUNDEnable IP Filter feature on the PLC via programming software to restrict network access to only trusted HMI and SCADA hosts
WORKAROUNDEnable password protection on the PLC within the programming software to prevent unauthorized download or modification of control logic
HARDENINGIsolate the PLC on a dedicated OT control network (air-gapped from office IT network and Internet)
HARDENINGDeploy a firewall between the OT network and any external networks; block all inbound traffic to the PLC except from known trusted hosts
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HARDENINGIf remote access is required, enforce use of a secure, authorized VPN tunnel with strong authentication
HOTFIXMonitor Delta Electronics advisory page for firmware patches and apply them immediately when available
API: /api/v1/advisories/4c3fd73a-55ce-4f6c-b755-42d3fbd32c8f

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Delta Electronics DVP12SE PLC | CVSS 9.8 - OTPulse