📦 Sge Plc1000 Firmware

by Circutor

🔍 What is Sge Plc1000 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-11788

CRITICAL CVSS 9.8 Dec 2, 2025

A heap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 allows remote code execution by sending an excessively large 'meter' parameter. This affects industrial control systems usi...

CVE-2025-11785

CRITICAL CVSS 9.8 Dec 2, 2025

A stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 allows remote code execution by sending an excessively large 'meter' parameter. This affects industrial control systems ru...

CVE-2025-11786

CRITICAL CVSS 9.8 Dec 2, 2025

This CVE describes a critical stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 devices. An attacker can inject arbitrary shell commands through the password change function,...

CVE-2025-11782

CRITICAL CVSS 9.8 Dec 2, 2025

A stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 allows remote code execution by sending an overly long 'meter' parameter. This affects industrial control systems using th...

CVE-2025-11783

CRITICAL CVSS 9.8 Dec 2, 2025

A stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2 allows remote attackers to execute arbitrary code by sending specially crafted username input. This affects industr...

CVE-2025-11784

CRITICAL CVSS 9.8 Dec 2, 2025

This CVE describes a critical stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 devices. An attacker can exploit this by sending excessively large input to the 'meter' parame...

CVE-2025-11779

CRITICAL CVSS 9.8 Dec 2, 2025

A stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2 allows remote attackers to execute arbitrary code via the 'SetLan' function in the management web interface. This a...

CVE-2025-11780

CRITICAL CVSS 9.8 Dec 2, 2025

This CVE describes a critical stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 devices. An attacker can exploit this by sending an excessively large 'meter' parameter to exe...

CVE-2025-11778

CRITICAL CVSS 9.8 Dec 2, 2025

A stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v0.9.2 allows remote attackers to execute arbitrary code through memory corruption in the TACACSPLUS implementation. This ...

CVE-2021-33841

CRITICAL CVSS 10.0 Jun 9, 2021

CVE-2021-33841 is a critical OS command injection vulnerability in the SGE-PLC1000 device's firmware, allowing remote attackers to execute arbitrary commands with root privileges. It affects users of ...

CVE-2025-11789

HIGH CVSS 7.5 Dec 2, 2025

An out-of-bounds read vulnerability in Circutor SGE-PLC1000/SGE-PLC50 allows attackers to read memory beyond intended boundaries by providing a large parameter to the 'DownloadFile' function. This aff...

CVE-2025-11787

HIGH CVSS 8.8 Dec 2, 2025

This CVE describes a command injection vulnerability in Circutor SGE-PLC1000/SGE-PLC50 devices that allows attackers to execute arbitrary commands on the operating system. The vulnerability exists in ...

CVE-2025-11781

HIGH CVSS 7.8 Dec 2, 2025

This vulnerability allows attackers with local access to extract a hardcoded cryptographic key from Circutor SGE-PLC1000/SGE-PLC50 devices. Using this key, they can create valid firmware update packag...