CVE-2026-3094 PUBLISHED

File Parsing Out-Of-Bounds Write in CNCSoft-G2

Assigner: Deltaww
Reserved: 24.02.2026 Published: 04.03.2026 Updated: 04.03.2026

Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Score: 7.8

Product Status

Vendor deltaww
Product CNCSoft-G2
Versions Default: unaffected
  • affected from 0 to 2.1.0.39 (excl.)

Solutions

Download and update to: v2.1.0.39 or later

Credits

  • Natnael Samson (@NattiSamson) working with TrendAI Zero Day Initiative reporter
  • Israel Bentley of CISA coordinator

References

Problem Types

  • CWE-787 Out-of-bounds Write CWE

Impacts

  • CAPEC-100 Overflow Buffers