DIAView - Authentication Bypass Vulnerability
Summary
| CVE | CVE-2025-62582 |
|---|---|
| State | PUBLISHED |
| Assigner | Deltaww |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-01-16 03:15:59 UTC |
| Updated | 2026-05-29 04:17:04 UTC |
| Description | Delta Electronics DIAView has multiple vulnerabilities. |
Risk And Classification
Primary CVSS: v3.1 9.8 CRITICAL from 759f5e80-c8e1-4224-bead-956d7b33c98b
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.000260000 probability, percentile 0.078330000 (date 2026-05-29)
Problem Types: CWE-306 | CWE-306 CWE-306 Missing Authentication for Critical Function
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 759f5e80-c8e1-4224-bead-956d7b33c98b | Secondary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Delta Electronics | DIAView | affected 4.3.1 custom | Windows |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| filecenter.deltaww.com/news/download/doc/Delta-PCSA-2026-00001_DIAView%20Multiple%20... | 759f5e80-c8e1-4224-bead-956d7b33c98b | filecenter.deltaww.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Tenable (en)
Additional Advisory Data
Solutions
CNA: Please download and upgrade DIAView to v4.4 or later. In addition, to prevent a potential verification bypass on the database under sophisticated technical analysis, users are strongly advised to enforce firewall isolation to completely restrict unauthorized remote access to the database.
There are currently no legacy QID mappings associated with this CVE.