Circutor

Sge-plc50 Firmware

12 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 02.12.2025 13:15:52
  • Zuletzt bearbeitet 03.12.2025 19:18:00

Out-of-bounds read vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'DownloadFile' function converts a parameter to an integer using 'atoi()' and then uses it as an index in the 'FilesDownload' array with '(&FilesDownload)[iVar2]'. If the ...

  • EPSS 0.06%
  • Veröffentlicht 02.12.2025 13:15:51
  • Zuletzt bearbeitet 03.12.2025 19:19:01

Heap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowSupervisorParameters()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(meter)' functio...

  • EPSS 0.07%
  • Veröffentlicht 02.12.2025 13:15:50
  • Zuletzt bearbeitet 03.12.2025 19:13:22

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterPasswords()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(meter)' function ret...

  • EPSS 0.07%
  • Veröffentlicht 02.12.2025 13:15:50
  • Zuletzt bearbeitet 03.12.2025 19:13:02

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'SetUserPassword()' function, the 'newPassword' parameter is directly embedded in a shell command string using 'sprintf()' without any sanitisation or validati...

  • EPSS 0.29%
  • Veröffentlicht 02.12.2025 13:15:50
  • Zuletzt bearbeitet 03.12.2025 19:16:37

Command injection vulnerability in the operating system in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2 through the 'GetDNS()', 'CheckPing()' and 'TraceRoute()' functions.

  • EPSS 0.02%
  • Veröffentlicht 02.12.2025 13:15:49
  • Zuletzt bearbeitet 03.12.2025 19:10:34

Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The affected firmware contains a hardcoded static authentication key. An attacker with local access to the device can extract this key (e.g., by analysing the firmware imag...

  • EPSS 0.07%
  • Veröffentlicht 02.12.2025 13:15:49
  • Zuletzt bearbeitet 03.12.2025 19:11:40

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'ShowDownload()' function uses “sprintf()” to format a string that includes the user-controlled input of 'GetParameter(meter)' in the fixed-size buffer 'acStack_4...

  • EPSS 0.24%
  • Veröffentlicht 02.12.2025 13:15:49
  • Zuletzt bearbeitet 03.12.2025 19:12:12

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The vulnerability is found in the 'AddEvent()' function when copying the user-controlled username input to a fixed-size buffer (48 bytes) without boundary checking. T...

  • EPSS 0.07%
  • Veröffentlicht 02.12.2025 13:15:49
  • Zuletzt bearbeitet 03.12.2025 19:12:25

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterDatabase()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(meter)' function retr...

  • EPSS 1.97%
  • Veröffentlicht 02.12.2025 13:15:48
  • Zuletzt bearbeitet 03.12.2025 19:07:24

Stack-based buffer overflow vulnerability in CircutorSGE-PLC1000/SGE-PLC50 v9.0.2. The 'SetLan' function is invoked when a new configuration is applied. This new configuration function is activated by a management web request, which can be invoked by...