VulnSea

circutor has 9 CVEs on record. The busiest recent month was December 2025 with 9. The median CVSS is 9.8 (critical), with 6 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-121 (5).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
9.8
Publish → KEV
—
Last 90 days
0 prev 0

Products

  • sge-plc1000_firmware 9
9
Total CVEs
6
Critical
0
CISA KEV
0
Exploited

circutor vulnerabilities

CVEs affecting circutor, newest first. Open any entry for full detail, references, and exploit status.

9 CVEsRSS

CVE-2025-11788Critical· 9.8
9mo ago

Heap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2

Heap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowSupervisorParameters()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(me…

▾ Midnightcircutor · sge-plc1000_firmwareEPSS 0.33%via NVD
CVE-2025-11787High· 8.8
9mo ago

Command injection vulnerability in the operating system in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2 through the 'GetDNS()', 'CheckPing()' and 'TraceRoute()' functions.

Command injection vulnerability in the operating system in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2 through the 'GetDNS()', 'CheckPing()' and 'TraceRoute()' functions.

▾ Twilightcircutor · sge-plc1000_firmwareEPSS 1.0%via NVD
CVE-2025-11786Critical· 9.8
9mo ago

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'SetUserPassword()' function, the 'newPassword' parameter is directly embedded in a shell command string using 'sprintf()' without any sanitisatio…

▾ Midnightcircutor · sge-plc1000_firmwareEPSS 0.37%via NVD
CVE-2025-11784Critical· 9.8
9mo ago

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterDatabase()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(meter)' …

▾ Midnightcircutor · sge-plc1000_firmwareEPSS 0.37%via NVD
CVE-2025-11783Critical· 9.8
9mo ago

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The vulnerability is found in the 'AddEvent()' function when copying the user-controlled username input to a fixed-size buffer (48 bytes) without boundar…

▾ Midnightcircutor · sge-plc1000_firmwareEPSS 0.58%via NVD
CVE-2025-11782Critical· 9.8
9mo ago

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'ShowDownload()' function uses “sprintf()” to format a string that includes the user-controlled input of 'GetParameter(meter)' in the fixed-size buff…

▾ Midnightcircutor · sge-plc1000_firmwareEPSS 0.37%via NVD
CVE-2025-11781High· 7.8
9mo ago

Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2

Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The affected firmware contains a hardcoded static authentication key. An attacker with local access to the device can extract this key (e.g., by analysing the …

▾ Twilightcircutor · sge-plc1000_firmwareEPSS 0.14%via NVD
CVE-2025-11779Critical· 9.8
9mo ago

Stack-based buffer overflow vulnerability in CircutorSGE-PLC1000/SGE-PLC50 v9.0.2

Stack-based buffer overflow vulnerability in CircutorSGE-PLC1000/SGE-PLC50 v9.0.2. The 'SetLan' function is invoked when a new configuration is applied. This new configuration function is activated by a management web request, which can …

▾ Midnightcircutor · sge-plc1000_firmwareEPSS 1.3%via NVD
CVE-2025-11789High· 7.5
9mo ago

Out-of-bounds read vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2

Out-of-bounds read vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'DownloadFile' function converts a parameter to an integer using 'atoi()' and then uses it as an index in the 'FilesDownload' array with '(&FilesDownload)[iVa…

▾ Twilightcircutor · sge-plc1000_firmwareEPSS 0.26%via NVD
circutor vulnerabilities (CVEs) · VulnSea