8.5

CVSS4.0

CVE-2025-11788 - Heap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50

Heap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowSupervisorParameters()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(meter)' function retrieves the user input, which is directly inc…

📅 Published: Dec. 2, 2025, 1:03 p.m. 🔄 Last Modified: Dec. 3, 2025, 7:19 p.m.

8.5

CVSS4.0

CVE-2025-11787 - Command injection vulnerability in Circutor SGE-PLC1000/SGE-PLC50

Command injection vulnerability in the operating system in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2 through the 'GetDNS()', 'CheckPing()' and 'TraceRoute()' functions.

📅 Published: Dec. 2, 2025, 1:02 p.m. 🔄 Last Modified: Dec. 3, 2025, 7:16 p.m.

8.5

CVSS4.0

CVE-2025-11786 - Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'SetUserPassword()' function, the 'newPassword' parameter is directly embedded in a shell command string using 'sprintf()' without any sanitisation or validation, and then executed using 'system()'. This allo…

📅 Published: Dec. 2, 2025, 1:01 p.m. 🔄 Last Modified: Dec. 3, 2025, 7:13 p.m.

8.5

CVSS4.0

CVE-2025-11785 - Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterPasswords()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(meter)' function retrieves the user input, which is directly incorpor…

📅 Published: Dec. 2, 2025, 1:01 p.m. 🔄 Last Modified: Dec. 3, 2025, 7:13 p.m.

8.5

CVSS4.0

CVE-2025-11784 - Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterDatabase()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(meter)' function retrieves the user input, which is directly incorpora…

📅 Published: Dec. 2, 2025, 1:01 p.m. 🔄 Last Modified: Dec. 3, 2025, 7:12 p.m.

8.5

CVSS4.0

CVE-2025-11783 - Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The vulnerability is found in the 'AddEvent()' function when copying the user-controlled username input to a fixed-size buffer (48 bytes) without boundary checking. This can lead to memory corruption, resulting in p…

📅 Published: Dec. 2, 2025, 1:01 p.m. 🔄 Last Modified: Dec. 3, 2025, 7:12 p.m.

8.5

CVSS4.0

CVE-2025-11782 - Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'ShowDownload()' function uses “sprintf()” to format a string that includes the user-controlled input of 'GetParameter(meter)' in the fixed-size buffer 'acStack_4c' (64 bytes) without checking the length. An att…

📅 Published: Dec. 2, 2025, 1 p.m. 🔄 Last Modified: Dec. 3, 2025, 7:11 p.m.

8.6

CVSS4.0

CVE-2025-11781 - Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50

Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The affected firmware contains a hardcoded static authentication key. An attacker with local access to the device can extract this key (e.g., by analysing the firmware image or memory dump) and create valid firmware updat…

📅 Published: Dec. 2, 2025, 12:59 p.m. 🔄 Last Modified: Dec. 3, 2025, 7:10 p.m.

8.7

CVSS4.0

CVE-2025-11780 - Stack-based buffer overflow vulnreability in Circutor SGE-PLC1000/SGE-PLC50

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'showMeterReport()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(meter)' function retrieves the user input, which is directly incorporate…

📅 Published: Dec. 2, 2025, 12:58 p.m. 🔄 Last Modified: Dec. 3, 2025, 7:08 p.m.

9.4

CVSS4.0

CVE-2025-11779 - Stack-based buffer overflow vulnreability in Circutor SGE-PLC1000/SGE-PLC50

Stack-based buffer overflow vulnerability in CircutorSGE-PLC1000/SGE-PLC50 v9.0.2. The 'SetLan' function is invoked when a new configuration is applied. This new configuration function is activated by a management web request, which can be invoked by a user when making changes to the 'index.cgi' we…

📅 Published: Dec. 2, 2025, 12:57 p.m. 🔄 Last Modified: Dec. 3, 2025, 7:07 p.m.
Total resulsts: 349182
Page 2850 of 34,919
« previous page » next page
Filters