Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.
CVE ID: CVE-2025-47728
CVSS Base Severity: HIGH
CVSS Base Score: 7.3
CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Vendor: Delta Electronics
Product: CNCSoft-G2
EPSS Score: 0.02% (probability of being exploited)
EPSS Percentile: 1.97% (scored less or equal to compared to others)
EPSS Date: 2025-06-05 (when was this score calculated)