Formula Injection Vulnerability in Delta Electronics DIALink Versions 1.2.4.0 and Prior

Formula Injection Vulnerability in Delta Electronics DIALink Versions 1.2.4.0 and Prior

CVE-2021-38424 · HIGH Severity

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

The tag interface of Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to an attacker injecting formulas into the tag data. Those formulas may then be executed when it is opened with a spreadsheet application.

Learn more about our Web Application Penetration Testing UK.