Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The vulnerability is found in the 'AddEvent()' function when copying the user-controlled username input to a fixed-size buffer (48 bytes) without boundary checking. This can lead to memory corruption, resulting in possible remote code execution.
Metrics
Affected Vendors & Products
References
History
Wed, 03 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Circutor
Circutor sge-plc1000 Circutor sge-plc1000 Firmware Circutor sge-plc50 Circutor sge-plc50 Firmware |
|
| CPEs | cpe:2.3:h:circutor:sge-plc1000:-:*:*:*:*:*:*:* cpe:2.3:h:circutor:sge-plc50:-:*:*:*:*:*:*:* cpe:2.3:o:circutor:sge-plc1000_firmware:9.0.2:*:*:*:*:*:*:* cpe:2.3:o:circutor:sge-plc50_firmware:9.0.2:*:*:*:*:*:*:* |
|
| Vendors & Products |
Circutor
Circutor sge-plc1000 Circutor sge-plc1000 Firmware Circutor sge-plc50 Circutor sge-plc50 Firmware |
|
| Metrics |
cvssV3_1
|
Tue, 02 Dec 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Dec 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The vulnerability is found in the 'AddEvent()' function when copying the user-controlled username input to a fixed-size buffer (48 bytes) without boundary checking. This can lead to memory corruption, resulting in possible remote code execution. | |
| Title | Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 | |
| First Time appeared |
Sge-plc1000 Sge-plc50
Sge-plc1000 Sge-plc50 circutor |
|
| Weaknesses | CWE-121 | |
| CPEs | cpe:2.3:a:sge-plc1000_sge-plc50:circutor:9.0.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Sge-plc1000 Sge-plc50
Sge-plc1000 Sge-plc50 circutor |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published: 2025-12-02T13:01:04.236Z
Updated: 2025-12-02T14:00:14.603Z
Reserved: 2025-10-15T12:06:12.926Z
Link: CVE-2025-11783
Updated: 2025-12-02T14:00:10.983Z
Status : Analyzed
Published: 2025-12-02T13:15:49.720
Modified: 2025-12-03T19:12:12.603
Link: CVE-2025-11783
No data.