Vulnerabilities
Vulnerable Software
Circutor:  >> Sge-Plc1000  Security Vulnerabilities
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'showMeterReport()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(meter)' function retrieves the user input, which is directly incorporated into a buffer without size validation. An attacker can provide an excessively large input for the “meter” parameter.
CVSS Score
9.8
EPSS Score
0.0
Published
2025-12-02
Stack-based buffer overflow in Circutor SGE-PLC1000/SGE-PLC50 v0.9.2. This vulnerability allows an attacker to remotely exploit memory corruption through the 'read_packet()' function of the TACACSPLUS implementation.
CVSS Score
9.8
EPSS Score
0.0
Published
2025-12-02
SGE-PLC1000 device, in its 0.9.2b firmware version, does not handle some requests correctly, allowing a remote attacker to inject code into the operating system with maximum privileges.
CVSS Score
10.0
EPSS Score
0.015
Published
2021-06-09
Improper Authentication vulnerability in the cookie parameter of Circutor SGE-PLC1000 firmware version 0.9.2b allows an attacker to perform operations as an authenticated user. In order to exploit this vulnerability, the attacker must be within the network where the device affected is located.
CVSS Score
8.8
EPSS Score
0.002
Published
2021-06-09


Contact Us

Shodan ® - All rights reserved