Stack-based buffer overflow vulnerability in CircutorSGE-PLC1000/SGE-PLC50 v9.0.2. The 'SetLan' function is invoked when a new configuration is applied. This new configuration function is activated by a management web request, which can be invoked by a user when making changes to the 'index.cgi' web application. The parameters are not being sanitised, which could lead to command injection.
The 'SetLan' function is called when applying new network configuration to the device. This configuration is initiated via an HTTP request to the 'index.cgi' web application, available to the logged-in user. The parameters passed to the function are not properly validated or sanitized, which enables injection of malicious data causing stack-based buffer overflow and potential execution of arbitrary commands.
An attacker with access to the local network and possessing basic user privileges can take control of the device by executing arbitrary system commands (command injection), which may result in complete device takeover and compromise of integrity, confidentiality and availability of both the device itself and systems connected to it.
Apply patches available from the manufacturer in accordance with the references (https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-circutor-products-0). Until the fix is implemented, it is recommended to restrict access to the device's web interface only to trusted hosts and isolate devices in a dedicated segment of the industrial network.
Circutor SGE-PLC1000 and SGE-PLC50 devices with firmware version 9.0.2.
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCircutor Sge Plc1000
HWCircutorall versionsCircutor Sge Plc1000 Firmware
OSCircutor9.0.2Circutor Sge Plc50
HWCircutorall versionsCircutor Sge Plc50 Firmware
OSCircutor9.0.2
Related vulnerabilities
Stack-based buffer overflow w Circutor SGE-PLC1000/SGE-PLC50 (TACACS+)
Command Injection w Circutor SGE-PLC1000 — zdalny dostęp z uprawnieniami root
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'showMeterReport()'...
Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The affected firmware contains a...
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'ShowDownload()' funct...