← Back

Circontrol

circontrol

10 CVEs • 6 products

Products (6)

Click to collapse
Toggle

CVEs (10)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Circontrol
1Raption Server
Jun 17, 2026
Apr 12, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
The server in Circontrol Raption through 5.11.2 has a pre-authentication stack-based buffer overflow that can be exploited to gain run-time control of the device as root. The ocpp1.5 and pwrstudio binaries on the chargin...Show more
The server in Circontrol Raption through 5.11.2 has a pre-authentication stack-based buffer overflow that can be exploited to gain run-time control of the device as root. The ocpp1.5 and pwrstudio binaries on the charging station do not use a number of common exploitation mitigations. In particular, there are no stack canaries and they do not use the Position Independent Executable (PIE) format.Show less
1Circontrol
1Circarlife Firmware
Nov 21, 2024
Nov 2, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Circontrol CirCarLife all versions prior to 4.3.1, the PAP credentials of the device are stored in clear text in a log file that is accessible without authentication.
1Circontrol
1Circarlife Firmware
Nov 21, 2024
Nov 2, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Circontrol CirCarLife all versions prior to 4.3.1, authentication to the device can be bypassed by entering the URL of a specific page.
1Circontrol
1Circarlife Scada
Nov 21, 2024
Sep 26, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in CIRCONTROL CirCarLife before 4.3. Due to the storage of multiple sensitive information elements in a JSON format at /services/system/setup.json, an authenticated but unprivileged user can exfil...Show more
An issue was discovered in CIRCONTROL CirCarLife before 4.3. Due to the storage of multiple sensitive information elements in a JSON format at /services/system/setup.json, an authenticated but unprivileged user can exfiltrate critical setup information.Show less
1Circontrol
1Circarlife Scada
Nov 21, 2024
Sep 18, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is system software information disclosure due to lack of authentication for /html/device-id.
1Circontrol
1Circarlife Scada
Nov 21, 2024
Sep 18, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is PLC status disclosure due to lack of authentication for /html/devstat.html.
1Circontrol
1Open Charge Point Protocol
Nov 21, 2024
Sep 18, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered in CIRCONTROL Open Charge Point Protocol (OCPP) before 1.5.0, as used in CirCarLife, PowerStudio, and other products. Due to storage of credentials in XML files, an unprivileged user can look at /...Show more
An issue was discovered in CIRCONTROL Open Charge Point Protocol (OCPP) before 1.5.0, as used in CirCarLife, PowerStudio, and other products. Due to storage of credentials in XML files, an unprivileged user can look at /services/config/config.xml for the admin credentials of the ocpp and circarlife panels.Show less
1Circontrol
1Circarlife Scada
Nov 21, 2024
Sep 18, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is internal installation path disclosure due to the lack of authentication for /html/repository.
1Circontrol
1Scada
Nov 21, 2024
Jun 22, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
CirCarLife Scada v4.2.4 allows unauthorized upgrades via requests to the html/upgrade.html and services/system/firmware.upgrade URIs.
1Circontrol
1Circarlife Scada
Nov 21, 2024
Jun 22, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/log or services/system/info.html URI.