CVEs (12)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Circutor 2Sge Plc1000 Firmware Sge Plc50 FirmwareDec 3, 2025 Dec 2, 2025 7.1 HIGH· v4 7.5 HIGH· v3 N/A· v2 Out-of-bounds read vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'DownloadFile' function converts a parameter to an integer using 'atoi()' and then uses it as an index in the 'FilesDownload' array with '(&F...Show more |
1Circutor 2Sge Plc1000 Firmware Sge Plc50 FirmwareDec 3, 2025 Dec 2, 2025 8.5 HIGH· v4 9.8 CRITICAL· v3 N/A· v2 Heap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowSupervisorParameters()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The...Show more |
1Circutor 2Sge Plc1000 Firmware Sge Plc50 FirmwareDec 3, 2025 Dec 2, 2025 8.5 HIGH· v4 8.8 HIGH· v3 N/A· v2 Command injection vulnerability in the operating system in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2 through the 'GetDNS()', 'CheckPing()' and 'TraceRoute()' functions. |
1Circutor 2Sge Plc1000 Firmware Sge Plc50 FirmwareDec 3, 2025 Dec 2, 2025 8.5 HIGH· v4 9.8 CRITICAL· v3 N/A· v2 Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'SetUserPassword()' function, the 'newPassword' parameter is directly embedded in a shell command string using 'sprintf()' withou...Show more |
1Circutor 2Sge Plc1000 Firmware Sge Plc50 FirmwareDec 3, 2025 Dec 2, 2025 8.5 HIGH· v4 9.8 CRITICAL· v3 N/A· v2 Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterPasswords()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'Get...Show more |
1Circutor 2Sge Plc1000 Firmware Sge Plc50 FirmwareDec 3, 2025 Dec 2, 2025 8.5 HIGH· v4 9.8 CRITICAL· v3 N/A· v2 Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterDatabase()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetP...Show more |
1Circutor 2Sge Plc1000 Firmware Sge Plc50 FirmwareDec 3, 2025 Dec 2, 2025 8.5 HIGH· v4 9.8 CRITICAL· v3 N/A· v2 Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The vulnerability is found in the 'AddEvent()' function when copying the user-controlled username input to a fixed-size buffer (48 bytes...Show more |
1Circutor 2Sge Plc1000 Firmware Sge Plc50 FirmwareDec 3, 2025 Dec 2, 2025 8.5 HIGH· v4 9.8 CRITICAL· v3 N/A· v2 Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'ShowDownload()' function uses “sprintf()” to format a string that includes the user-controlled input of 'GetParameter(meter)' in th...Show more |
1Circutor 2Sge Plc1000 Firmware Sge Plc50 FirmwareDec 3, 2025 Dec 2, 2025 8.6 HIGH· v4 7.8 HIGH· v3 N/A· v2 Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The affected firmware contains a hardcoded static authentication key. An attacker with local access to the device can extract this key (e.g.,...Show more |
1Circutor 2Sge Plc1000 Firmware Sge Plc50 FirmwareDec 3, 2025 Dec 2, 2025 8.7 HIGH· v4 9.8 CRITICAL· v3 N/A· v2 Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'showMeterReport()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetPar...Show more |
1Circutor 2Sge Plc1000 Firmware Sge Plc50 FirmwareDec 3, 2025 Dec 2, 2025 9.4 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Stack-based buffer overflow vulnerability in CircutorSGE-PLC1000/SGE-PLC50 v9.0.2. The 'SetLan' function is invoked when a new configuration is applied. This new configuration function is activated by a management web re...Show more |
1Circutor 2Sge Plc1000 Firmware Sge Plc50 FirmwareDec 3, 2025 Dec 2, 2025 10.0 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Stack-based buffer overflow in Circutor SGE-PLC1000/SGE-PLC50 v0.9.2. This vulnerability allows an attacker to remotely exploit memory corruption through the 'read_packet()' function of the TACACSPLUS implementation. |