CVE-2025-11789
- EPSS 0.05%
- Veröffentlicht 02.12.2025 13:15:52
- Zuletzt bearbeitet 03.12.2025 19:18:00
Out-of-bounds read vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'DownloadFile' function converts a parameter to an integer using 'atoi()' and then uses it as an index in the 'FilesDownload' array with '(&FilesDownload)[iVar2]'. If the ...
CVE-2025-11785
- EPSS 0.07%
- Veröffentlicht 02.12.2025 13:15:50
- Zuletzt bearbeitet 03.12.2025 19:13:22
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterPasswords()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(meter)' function ret...
CVE-2025-11786
- EPSS 0.07%
- Veröffentlicht 02.12.2025 13:15:50
- Zuletzt bearbeitet 03.12.2025 19:13:02
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'SetUserPassword()' function, the 'newPassword' parameter is directly embedded in a shell command string using 'sprintf()' without any sanitisation or validati...
CVE-2025-11787
- EPSS 0.29%
- Veröffentlicht 02.12.2025 13:15:50
- Zuletzt bearbeitet 03.12.2025 19:16:37
Command injection vulnerability in the operating system in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2 through the 'GetDNS()', 'CheckPing()' and 'TraceRoute()' functions.
CVE-2025-11781
- EPSS 0.02%
- Veröffentlicht 02.12.2025 13:15:49
- Zuletzt bearbeitet 03.12.2025 19:10:34
Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The affected firmware contains a hardcoded static authentication key. An attacker with local access to the device can extract this key (e.g., by analysing the firmware imag...
CVE-2025-11782
- EPSS 0.07%
- Veröffentlicht 02.12.2025 13:15:49
- Zuletzt bearbeitet 03.12.2025 19:11:40
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'ShowDownload()' function uses “sprintf()” to format a string that includes the user-controlled input of 'GetParameter(meter)' in the fixed-size buffer 'acStack_4...
CVE-2025-11783
- EPSS 0.24%
- Veröffentlicht 02.12.2025 13:15:49
- Zuletzt bearbeitet 03.12.2025 19:12:12
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The vulnerability is found in the 'AddEvent()' function when copying the user-controlled username input to a fixed-size buffer (48 bytes) without boundary checking. T...
CVE-2025-11784
- EPSS 0.07%
- Veröffentlicht 02.12.2025 13:15:49
- Zuletzt bearbeitet 03.12.2025 19:12:25
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterDatabase()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(meter)' function retr...
CVE-2025-11779
- EPSS 1.97%
- Veröffentlicht 02.12.2025 13:15:48
- Zuletzt bearbeitet 03.12.2025 19:07:24
Stack-based buffer overflow vulnerability in CircutorSGE-PLC1000/SGE-PLC50 v9.0.2. The 'SetLan' function is invoked when a new configuration is applied. This new configuration function is activated by a management web request, which can be invoked by...
CVE-2025-11780
- EPSS 0.06%
- Veröffentlicht 02.12.2025 13:15:48
- Zuletzt bearbeitet 03.12.2025 19:08:11
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'showMeterReport()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(meter)' function retrie...