CRITICAL🇵🇱 Wersja polska

CVE-2025-11779

CVSS 9.4v4.0pub. 2025-12-02upd. 2025-12-03

Stack-based buffer overflow vulnerability in CircutorSGE-PLC1000/SGE-PLC50 v9.0.2. The 'SetLan' function is invoked when a new configuration is applied. This new configuration function is activated by a management web request, which can be invoked by a user when making changes to the 'index.cgi' web application. The parameters are not being sanitised, which could lead to command injection.

🤖 AI Analysis
How it works

The 'SetLan' function is called when applying new network configuration to the device. This configuration is initiated via an HTTP request to the 'index.cgi' web application, available to the logged-in user. The parameters passed to the function are not properly validated or sanitized, which enables injection of malicious data causing stack-based buffer overflow and potential execution of arbitrary commands.

Impact

An attacker with access to the local network and possessing basic user privileges can take control of the device by executing arbitrary system commands (command injection), which may result in complete device takeover and compromise of integrity, confidentiality and availability of both the device itself and systems connected to it.

Mitigation & patch

Apply patches available from the manufacturer in accordance with the references (https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-circutor-products-0). Until the fix is implemented, it is recommended to restrict access to the device's web interface only to trusted hosts and isolate devices in a dedicated segment of the industrial network.

Who is affected

Circutor SGE-PLC1000 and SGE-PLC50 devices with firmware version 9.0.2.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Circutor Sge Plc1000

    HW
    Circutor
    all versions
  • Circutor Sge Plc1000 Firmware

    OS
    Circutor
    9.0.2
  • Circutor Sge Plc50

    HW
    Circutor
    all versions
  • Circutor Sge Plc50 Firmware

    OS
    Circutor
    9.0.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2025-11778CRITICAL10.0PL ✓same product

Stack-based buffer overflow w Circutor SGE-PLC1000/SGE-PLC50 (TACACS+)

CVE-2021-33841CRITICAL10.0PL ✓same product

Command Injection w Circutor SGE-PLC1000 — zdalny dostęp z uprawnieniami root

CVE-2025-11780HIGH8.7same product

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'showMeterReport()'...

CVE-2025-11781HIGH8.6same product

Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The affected firmware contains a...

CVE-2025-11782HIGH8.5same product

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'ShowDownload()' funct...