Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'SetUserPassword()' function, the 'newPassword' parameter is directly embedded in a shell command string using 'sprintf()' without any sanitisation or validation, and then executed using 'system()'. This allows an attacker to inject arbitrary shell commands that will be executed with the same privileges as the application.
History

Wed, 03 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Circutor
Circutor sge-plc1000
Circutor sge-plc1000 Firmware
Circutor sge-plc50
Circutor sge-plc50 Firmware
CPEs cpe:2.3:h:circutor:sge-plc1000:-:*:*:*:*:*:*:*
cpe:2.3:h:circutor:sge-plc50:-:*:*:*:*:*:*:*
cpe:2.3:o:circutor:sge-plc1000_firmware:9.0.2:*:*:*:*:*:*:*
cpe:2.3:o:circutor:sge-plc50_firmware:9.0.2:*:*:*:*:*:*:*
Vendors & Products Circutor
Circutor sge-plc1000
Circutor sge-plc1000 Firmware
Circutor sge-plc50
Circutor sge-plc50 Firmware
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Tue, 02 Dec 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 02 Dec 2025 13:15:00 +0000

Type Values Removed Values Added
Description Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'SetUserPassword()' function, the 'newPassword' parameter is directly embedded in a shell command string using 'sprintf()' without any sanitisation or validation, and then executed using 'system()'. This allows an attacker to inject arbitrary shell commands that will be executed with the same privileges as the application.
Title Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50
First Time appeared Sge-plc1000 Sge-plc50
Sge-plc1000 Sge-plc50 circutor
Weaknesses CWE-121
CPEs cpe:2.3:a:sge-plc1000_sge-plc50:circutor:9.0.2:*:*:*:*:*:*:*
Vendors & Products Sge-plc1000 Sge-plc50
Sge-plc1000 Sge-plc50 circutor
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2025-12-02T13:01:37.231Z

Updated: 2025-12-02T13:36:41.564Z

Reserved: 2025-10-15T12:06:16.258Z

Link: CVE-2025-11786

cve-icon Vulnrichment

Updated: 2025-12-02T13:36:38.157Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-02T13:15:50.493

Modified: 2025-12-03T19:13:02.350

Link: CVE-2025-11786

cve-icon Redhat

No data.