CVE-2025-22882

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Apr 30, 2025
Updated: May 2, 2025

Summary

CVE-2025-22882 is a critical vulnerability affecting Delta Electronics ISPSoft version 3.20. This issue involves a stack-based buffer overflow, which can be exploited by an attacker to execute arbitrary code. The vulnerability is found in the software's handling of CBDGL files during parsing. An attacker can leverage debugging logic to trigger the overflow, potentially leading to code execution with elevated privileges. Organizations using ISPSoft version 3.20 are strongly advised to apply the available patch or upgrade to a secure version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share