Stack-based buffer overflow vulnerability in CircutorSGE-PLC1000/SGE-PLC50 v9.0.2. The 'SetLan' function is invoked when a new configuration is applied. This new configuration function is activated by a management web request, which can be invoked by a user when making changes to the 'index.cgi' web application. The parameters are not being sanitised, which could lead to command injection.
Metrics
Affected Vendors & Products
References
History
Tue, 02 Dec 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Dec 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stack-based buffer overflow vulnerability in CircutorSGE-PLC1000/SGE-PLC50 v9.0.2. The 'SetLan' function is invoked when a new configuration is applied. This new configuration function is activated by a management web request, which can be invoked by a user when making changes to the 'index.cgi' web application. The parameters are not being sanitised, which could lead to command injection. | |
| Title | Stack-based buffer overflow vulnreability in Circutor SGE-PLC1000/SGE-PLC50 | |
| First Time appeared |
Sge-plc1000 Sge-plc50
Sge-plc1000 Sge-plc50 circutor |
|
| Weaknesses | CWE-121 | |
| CPEs | cpe:2.3:a:sge-plc1000_sge-plc50:circutor:9.0.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Sge-plc1000 Sge-plc50
Sge-plc1000 Sge-plc50 circutor |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published: 2025-12-02T12:57:46.050Z
Updated: 2025-12-02T13:44:57.270Z
Reserved: 2025-10-15T12:06:08.399Z
Link: CVE-2025-11779
Updated: 2025-12-02T13:44:51.410Z
Status : Awaiting Analysis
Published: 2025-12-02T13:15:48.583
Modified: 2025-12-02T17:16:29.163
Link: CVE-2025-11779
No data.