Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The affected firmware contains a hardcoded static authentication key. An attacker with local access to the device can extract this key (e.g., by analysing the firmware image or memory dump) and create valid firmware update packages. This bypasses all intended access controls and grants full administrative privileges.
Metrics
Affected Vendors & Products
References
History
Wed, 03 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Circutor
Circutor sge-plc1000 Circutor sge-plc1000 Firmware Circutor sge-plc50 Circutor sge-plc50 Firmware |
|
| CPEs | cpe:2.3:h:circutor:sge-plc1000:-:*:*:*:*:*:*:* cpe:2.3:h:circutor:sge-plc50:-:*:*:*:*:*:*:* cpe:2.3:o:circutor:sge-plc1000_firmware:9.0.2:*:*:*:*:*:*:* cpe:2.3:o:circutor:sge-plc50_firmware:9.0.2:*:*:*:*:*:*:* |
|
| Vendors & Products |
Circutor
Circutor sge-plc1000 Circutor sge-plc1000 Firmware Circutor sge-plc50 Circutor sge-plc50 Firmware |
|
| Metrics |
cvssV3_1
|
Tue, 02 Dec 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Dec 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The affected firmware contains a hardcoded static authentication key. An attacker with local access to the device can extract this key (e.g., by analysing the firmware image or memory dump) and create valid firmware update packages. This bypasses all intended access controls and grants full administrative privileges. | |
| Title | Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 | |
| First Time appeared |
Sge-plc1000 Sge-plc50
Sge-plc1000 Sge-plc50 circutor |
|
| Weaknesses | CWE-321 | |
| CPEs | cpe:2.3:a:sge-plc1000_sge-plc50:circutor:9.0.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Sge-plc1000 Sge-plc50
Sge-plc1000 Sge-plc50 circutor |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published: 2025-12-02T12:59:46.925Z
Updated: 2025-12-02T13:35:07.164Z
Reserved: 2025-10-15T12:06:10.689Z
Link: CVE-2025-11781
Updated: 2025-12-02T13:35:02.532Z
Status : Analyzed
Published: 2025-12-02T13:15:49.140
Modified: 2025-12-03T19:10:34.340
Link: CVE-2025-11781
No data.